sssd-ipa-1.16.5-10.el7_9.6>t  DH`p_q$ƨQQaiXS0/&[p%Ҏ Kۄl??% 8+*/FjpBS^+p՘h3CK!5e)_WSO=f4Ӌc%@,:u~ ;ZYuZ~Rݯ2"̀g,_nKu^lVt]lGO-n(I~[0`;=߮m쒌c?뤈?䝘Il4zévnV!I5}ЏKn1(4Ht{Xzo);@0y 1XpϾyӹGj}xrLa؈77U+)EnT9-M2D" dB3"E T")Vr.M/桯l jUX+ABܩM䈈 + Ic dSwAE$ڽ5ђ~kC|?x4Rku!/$F9^a0%jY?ZgSMG R2j}Wz.KBy%G9 Pu0h, Em'N.9 Z' >=$4?$$d   : "?EL    @  @`TTuTHLQ(`8h@9h@:2@=MGXHxIXY\]^^bdefltu v 8w"|x"y"Y$ Csssd-ipa1.16.510.el7_9.6The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server._x86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64getent group sssd >/dev/null || groupadd -r sssd getent passwd sssd >/dev/null || useradd -r -g sssd -d / -s /sbin/nologin -c "User for sssd" sssd $Ks&/A큤A___^p0____84af42732f9b88126b850a11de0074b9fcef8d5df31eb9405adb4e123768cae91587a1270367584df5cb6847835019849aa73199d34f23b191ace0558f8502558ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9031cfd77e619bde9c4623921c1fb14b57ed137f043df7dd0b3f639a566403feb992bedea46c0d2dca2ce913178e0a6cae6dda1e423498782511a26508e941c5a358a714fbcd3632f9e54b1d9ae111f45903be25a1a8090c561f7e63c758362d8d4rootrootrootrootrootrootrootsssdrootsssdrootrootrootrootrootsssdsssd-1.16.5-10.el7_9.6.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@   @  /bin/shbind-utilslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcollection.so.2()(64bit)libcom_err.so.2()(64bit)libcrypto.so.10()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.3()(64bit)libipa_hbac(x86-64)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libipa_hbac.so.0(IPA_HBAC_0.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.1()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rtld(GNU_HASH)samba-client-libsshadow-utilssssd-commonsssd-common-pacsssd-krb5-commonrpmlib(PayloadIsXz)1.16.5-10.el7_9.61.16.5-10.el7_9.63.0.4-14.6.0-14.0-14.10.16-7.el7_91.16.5-10.el7_9.61.16.5-10.el7_9.61.16.5-10.el7_9.65.2-1sssd1.10.0-8.beta24.11.3_G@_H_H_=@_;_;^3^@^V@^m@^^@^>@^@^@^t@^r @^^@]]*]@]]]@]@]m]m]p]p]p]p]S\Q\Q\"\"\"\\\r@\r@\r@\\\\\\\\\\\|\+@[@[_[@[@[l,[b@[a[Y[Y[H@[E@[6@[0@[,[,[d@[[Z@Z@ZmZ@Z_@Z_@Z@ZyZhu@Z3@Z2gZ.s@Z*~Z'Z!D@ZZ@Z Z @Z7ZNYZ@Y@YYJ_YJ_YC@YBvYBvY9<@Y9<@Y5GY5GY5GY5GY0Y0Y(Y(Y%uY%uY$$@Y$$@Y"Y;@YR@YR@Y Y @Y @YtYtYtYtYtYXXh@XXX@X@X@XsX@X@X@XۡXۡXXӸX,XCX@XX*X lX lX lW$WW;W;W;W֘W֘W@W^@WiWiWiW/@W/@W/@W/@WWWWQWQWQW@W@W@WhW@W@Wt@WE@WE@W@W@W@W@WW~W-@W-@W-@WW@WWu WgWDB@WDB@WDB@WBW;W;W@VbV͛@VTQ@VCV @V @V @V V@VBVBVBVBVBUUUU@UXU@U@U@UUUUUUUUL@UL@UU@U@U@UnU@U(U@U@UUmUmU@UJ@UU7@U7@U7@U @U@U@TE@TE@TE@Tи@Tr@Tr@Tr@Tr@T}T}T}T}T}T7T7TTC@TTZ@TZ@TT@Tp@Tp@T@T{T*@T*@TTT~@T~@TuTuTto@Tto@Tto@Tto@Tto@Tto@TmTmTmTmTl@Tl@Tl@Tl@TcKTa@T\@TZ@TZ@TR(@TG@TG@TG@TG@TG@TD@T6xTTT SS@S|@Sr @Sr @Sr @Sr @S;S;S2@S2@S,)S!S L@SSS@S@S@S@S@S @S @S @S @S @S @S @S @SSSRb@Rb@Rb@R@R@R@R@RURURUR߲RRRx@Rx@Rx@RΏ@RΏ@RΏ@R=R=RkRRRR@R@R@R@R@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@Rv@RpREs@REs@R7Q@Q@Q@Q@Q@QQLQکQQQo@Q)@Q@QQ@Q@QbQyQV@Q'@QQQnQZ@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj 1.16.5-10.6Alexey Tikhonov 1.16.5-10.5Alexey Tikhonov 1.16.5-10.4Alexey Tikhonov 1.16.5-10.3Alexey Tikhonov 1.16.5-10.2Alexey Tikhonov 1.16.5-10.1Alexey Tikhonov 1.16.5-10Alexey Tikhonov 1.16.5-9Alexey Tikhonov 1.16.5-8Alexey Tikhonov 1.16.5-7Alexey Tikhonov 1.16.5-6Alexey Tikhonov 1.16.5-5Alexey Tikhonov 1.16.5-4Alexey Tikhonov 1.16.5-3Alexey Tikhonov 1.16.5-2Alexey Tikhonov 1.16.5-1Michal Židek - 1.16.4-38Michal Židek - 1.16.4-37Michal Židek - 1.16.4-36Michal Židek - 1.16.4-35Michal Židek - 1.16.4-34Michal Židek - 1.16.4-33Michal Židek - 1.16.4-32Michal Židek - 1.16.4-31Michal Židek - 1.16.4-30Michal Židek - 1.16.4-29Michal Židek - 1.16.4-28Michal Židek - 1.16.4-27Michal Židek - 1.16.4-26Michal Židek - 1.16.4-25Michal Židek - 1.16.4-24Michal Židek - 1.16.4-23Michal Židek - 1.16.4-22Michal Židek - 1.16.4-21Michal Židek - 1.16.4-20Jakub Hrozek - 1.16.4-19Jakub Hrozek - 1.16.4-18Jakub Hrozek - 1.16.4-17Michal Židek - 1.16.4-16Jakub Hrozek - 1.16.4-15Michal Židek - 1.16.4-14Michal Židek - 1.16.4-12Michal Židek - 1.16.4-12Michal Židek - 1.16.4-11Michal Židek - 1.16.4-10Michal Židek - 1.16.4-9Michal Židek - 1.16.4-8Michal Židek - 1.16.4-7Michal Židek - 1.16.4-6Michal Židek - 1.16.4-5Michal Židek - 1.16.4-4Michal Židek - 1.16.4-3Michal Židek - 1.16.4-2Michal Židek - 1.16.4-1Jakub Hrozek - 1.16.2-17Michal Židek - 1.16.2-16Michal Židek - 1.16.2-15Michal Židek - 1.16.2-14Jakub Hrozek - 1.16.2-13Fabiano Fidêncio - 1.16.2-12Jakub Hrozek - 1.16.2-11Jakub Hrozek - 1.16.2-10Jakub Hrozek - 1.16.2-9Jakub Hrozek - 1.16.2-8Fabiano Fidêncio - 1.16.2-7Fabiano Fidêncio - 1.16.2-6Fabiano Fidêncio - 1.16.2-5Fabiano Fidêncio - 1.16.2-4Fabiano Fidêncio - 1.16.2-3Fabiano Fidêncio - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.0-25Fabiano Fidêncio - 1.16.0-24Fabiano Fidêncio - 1.16.0-23Fabiano Fidêncio - 1.16.0-22Jakub Hrozek - 1.16.0-21Fabiano Fidêncio - 1.16.0-20Fabiano Fidêncio - 1.16.0-19Fabiano Fidêncio - 1.16.0-18Fabiano Fidêncio - 1.16.0-17Fabiano Fidêncio - 1.16.0-16Fabiano Fidêncio - 1.16.0-15Fabiano Fidêncio - 1.16.0-14Fabiano Fidêncio - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Fabiano Fidêncio - 1.16.0-11Fabiano Fidêncio - 1.16.0-10Fabiano Fidêncio - 1.16.0-9Fabiano Fidêncio - 1.16.0-8Fabiano Fidêncio - 1.16.0-7Fabiano Fidêncio - 1.16.0-6Fabiano Fidêncio - 1.16.0-5Fabiano Fidêncio - 1.16.0-4Fabiano Fidêncio - 1.16.0-3Fabiano Fidêncio - 1.16.0-2Fabiano Fidêncio - 1.16.0-1Jakub Hrozek - 1.15.2-51Jakub Hrozek - 1.15.2-50Jakub Hrozek - 1.15.2-49Jakub Hrozek - 1.15.2-48Jakub Hrozek - 1.15.2-47Jakub Hrozek - 1.15.2-46Jakub Hrozek - 1.15.2-45Jakub Hrozek - 1.15.2-44Jakub Hrozek - 1.15.2-43Jakub Hrozek - 1.15.2-42Jakub Hrozek - 1.15.2-41Jakub Hrozek - 1.15.2-40Jakub Hrozek - 1.15.2-39Jakub Hrozek - 1.15.2-38Jakub Hrozek - 1.15.2-37Jakub Hrozek - 1.15.2-36Jakub Hrozek - 1.15.2-35Jakub Hrozek - 1.15.2-34Jakub Hrozek - 1.15.2-33Jakub Hrozek - 1.15.2-32Jakub Hrozek - 1.15.2-31Sumit Bose - 1.15.2-30Jakub Hrozek - 1.15.2-29Jakub Hrozek - 1.15.2-28Jakub Hrozek - 1.15.2-25Jakub Hrozek - 1.15.2-24Lukas Slebodnik - 1.15.2-23Jakub Hrozek - 1.15.2-22Jakub Hrozek - 1.15.2-21Jakub Hrozek - 1.15.2-20Jakub Hrozek - 1.15.2-19Jakub Hrozek - 1.15.2-18Jakub Hrozek - 1.15.2-17Jakub Hrozek - 1.15.2-16Jakub Hrozek - 1.15.2-15Jakub Hrozek - 1.15.2-14Jakub Hrozek - 1.15.2-13Jakub Hrozek - 1.15.2-12Jakub Hrozek - 1.15.2-11Jakub Hrozek - 1.15.2-10Jakub Hrozek - 1.15.2-9Jakub Hrozek - 1.15.2-8Jakub Hrozek - 1.15.2-7Jakub Hrozek - 1.15.2-6Jakub Hrozek - 1.15.2-5Jakub Hrozek - 1.15.2-4Jakub Hrozek - 1.15.2-3Jakub Hrozek - 1.15.2-2Jakub Hrozek - 1.15.2-1Fabiano Fidêncio - 1.15.1-2Jakub Hrozek - 1.15.1-1Jakub Hrozek - 1.15.0-2Jakub Hrozek - 1.15.0-1Jakub Hrozek - 1.14.0-46Jakub Hrozek - 1.14.0-45Jakub Hrozek - 1.14.0-44Jakub Hrozek - 1.14.0-43Jakub Hrozek - 1.14.0-42Jakub Hrozek - 1.14.0-41Jakub Hrozek - 1.14.0-40Jakub Hrozek - 1.14.0-39Jakub Hrozek - 1.14.0-38Jakub Hrozek - 1.14.0-37Jakub Hrozek - 1.14.0-36Jakub Hrozek - 1.14.0-35Jakub Hrozek - 1.14.0-34Jakub Hrozek - 1.14.0-33Jakub Hrozek - 1.14.0-32Jakub Hrozek - 1.14.0-31Jakub Hrozek - 1.14.0-30Jakub Hrozek - 1.14.0-29Jakub Hrozek - 1.14.0-28Jakub Hrozek - 1.14.0-27Jakub Hrozek - 1.14.0-26Jakub Hrozek - 1.14.0-25Jakub Hrozek - 1.14.0-24Jakub Hrozek - 1.14.0-23Jakub Hrozek - 1.14.0-22Jakub Hrozek - 1.14.0-21Jakub Hrozek - 1.14.0-20Jakub Hrozek - 1.14.0-19Jakub Hrozek - 1.14.0-18Jakub Hrozek - 1.14.0-17Jakub Hrozek - 1.14.0-16Jakub Hrozek - 1.14.0-15Jakub Hrozek - 1.14.0-14Jakub Hrozek - 1.14.0-13Jakub Hrozek - 1.14.0-12Jakub Hrozek - 1.14.0-11Jakub Hrozek - 1.14.0-10Jakub Hrozek - 1.14.0-9Jakub Hrozek - 1.14.0-8Jakub Hrozek - 1.14.0-7Jakub Hrozek - 1.14.0-6Jakub Hrozek - 1.14.0-5Jakub Hrozek - 1.14.0-4Jakub Hrozek - 1.14.0-3Jakub Hrozek - 1.14.0-2Jakub Hrozek - 1.14.0-1Jakub Hrozek - 1.14.0beta1-2Jakub Hrozek - 1.14.0alpha-1Jakub Hrozek - 1.13.0-50Jakub Hrozek - 1.13.0-49Jakub Hrozek - 1.13.0-48Jakub Hrozek - 1.13.0-47Jakub Hrozek - 1.13.0-46Jakub Hrozek - 1.13.0-45Jakub Hrozek - 1.13.0-44Jakub Hrozek - 1.13.0-43Jakub Hrozek - 1.13.0-42Jakub Hrozek - 1.13.0-41Jakub Hrozek - 1.13.0-40Jakub Hrozek - 1.13.0-39Jakub Hrozek - 1.13.0-38Jakub Hrozek - 1.13.0-37Jakub Hrozek - 1.13.0-36Jakub Hrozek - 1.13.0-35Jakub Hrozek - 1.13.0-34Jakub Hrozek - 1.13.0-33Jakub Hrozek - 1.13.0-32Jakub Hrozek - 1.13.0-31Jakub Hrozek - 1.13.0-30Jakub Hrozek - 1.13.0-29Jakub Hrozek - 1.13.0-28Jakub Hrozek - 1.13.0-27Jakub Hrozek - 1.13.0-26Martin Kosek - 1.13.0-25Jakub Hrozek - 1.13.0-24Jakub Hrozek - 1.13.0-23Jakub Hrozek - 1.13.0-22Jakub Hrozek - 1.13.0-21Jakub Hrozek - 1.13.0-20Jakub Hrozek - 1.13.0-19Jakub Hrozek - 1.13.0-18Jakub Hrozek - 1.13.0-17Jakub Hrozek - 1.13.0-16Jakub Hrozek - 1.13.0-15Jakub Hrozek - 1.13.0-14Lukas Slebodnik - 1.13.0-13Jakub Hrozek - 1.13.0-12Jakub Hrozek - 1.13.0-11Jakub Hrozek - 1.13.0-10Jakub Hrozek - 1.13.0-9Jakub Hrozek - 1.13.0-8Jakub Hrozek - 1.13.0-7Jakub Hrozek - 1.13.0-6Jakub Hrozek - 1.13.0-5Jakub Hrozek - 1.13.0-4Jakub Hrozek - 1.13.0-3Jakub Hrozek - 1.13.0-2Jakub Hrozek - 1.13.0-1Jakub Hrozek - 1.13.0.3alphaJakub Hrozek - 1.13.0.2alphaJakub Hrozek - 1.13.0.1alphaJakub Hrozek - 1.12.2-61Jakub Hrozek - 1.12.2-60Jakub Hrozek - 1.12.2-59Jakub Hrozek - 1.12.2-58.6Jakub Hrozek - 1.12.2-58.5Jakub Hrozek - 1.12.2-58.4Jakub Hrozek - 1.12.2-58.3Jakub Hrozek - 1.12.2-58.2Jakub Hrozek - 1.12.2-58.1Jakub Hrozek - 1.12.2-57Jakub Hrozek - 1.12.2-56Jakub Hrozek - 1.12.2-55Jakub Hrozek - 1.12.2-54Jakub Hrozek - 1.12.2-53Jakub Hrozek - 1.12.2-52Jakub Hrozek - 1.12.2-51Jakub Hrozek - 1.12.2-50Jakub Hrozek - 1.12.2-49Jakub Hrozek - 1.12.2-48Jakub Hrozek - 1.12.2-47Jakub Hrozek - 1.12.2-46Jakub Hrozek - 1.12.2-45Jakub Hrozek - 1.12.2-44Jakub Hrozek - 1.12.2-43Jakub Hrozek - 1.12.2-42Jakub Hrozek - 1.12.2-41Jakub Hrozek - 1.12.2-40Sumit Bose - 1.12.2-39Sumit Bose - 1.12.2-38Sumit Bose - 1.12.2-37Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-35Jakub Hrozek - 1.12.2-34Jakub Hrozek - 1.12.2-33Jakub Hrozek - 1.12.2-32Jakub Hrozek - 1.12.2-31Jakub Hrozek - 1.12.2-30Jakub Hrozek - 1.12.2-29Jakub Hrozek - 1.12.2-28Jakub Hrozek - 1.12.2-27Jakub Hrozek - 1.12.2-26Jakub Hrozek - 1.12.2-25Jakub Hrozek - 1.12.2-24Jakub Hrozek - 1.12.2-23Jakub Hrozek - 1.12.2-22Jakub Hrozek - 1.12.2-21Jakub Hrozek - 1.12.2-20Jakub Hrozek - 1.12.2-19Jakub Hrozek - 1.12.2-18Jakub Hrozek - 1.12.2-17Jakub Hrozek - 1.12.2-16Jakub Hrozek - 1.12.2-15Jakub Hrozek - 1.12.2-14Jakub Hrozek - 1.12.2-13Jakub Hrozek - 1.12.2-12Jakub Hrozek - 1.12.2-11Jakub Hrozek - 1.12.2-10Jakub Hrozek - 1.12.2-9Jakub Hrozek - 1.12.2-8Jakub Hrozek - 1.12.2-7Jakub Hrozek - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-3Jakub Hrozek - 1.12.0-2Jakub Hrozek - 1.12.0-1Jakub Hrozek - 1.11.2-70Jakub Hrozek - 1.11.2-69Jakub Hrozek - 1.11.2-68Jakub Hrozek - 1.11.2-67Jakub Hrozek - 1.11.2-66Jakub Hrozek - 1.11.2-65Jakub Hrozek - 1.11.2-64Sumit Bose - 1.11.2-63Sumit Bose - 1.11.2-62Jakub Hrozek - 1.11.2-61Jakub Hrozek - 1.11.2-60Jakub Hrozek - 1.11.2-59Jakub Hrozek - 1.11.2-58Jakub Hrozek - 1.11.2-57Jakub Hrozek - 1.11.2-56Jakub Hrozek - 1.11.2-55Jakub Hrozek - 1.11.2-54Jakub Hrozek - 1.11.2-53Jakub Hrozek - 1.11.2-52Jakub Hrozek - 1.11.2-51Jakub Hrozek - 1.11.2-50Jakub Hrozek - 1.11.2-49Jakub Hrozek - 1.11.2-48Jakub Hrozek - 1.11.2-47Jakub Hrozek - 1.11.2-46Jakub Hrozek - 1.11.2-45Jakub Hrozek - 1.11.2-44Jakub Hrozek - 1.11.2-43Jakub Hrozek - 1.11.2-42Jakub Hrozek - 1.11.2-41Jakub Hrozek - 1.11.2-40Jakub Hrozek - 1.11.2-39Jakub Hrozek - 1.11.2-38Jakub Hrozek - 1.11.2-37Jakub Hrozek - 1.11.2-36Jakub Hrozek - 1.11.2-35Jakub Hrozek - 1.11.2-34Daniel Mach - 1.11.2-33Jakub Hrozek - 1.11.2-32Jakub Hrozek - 1.11.2-31Jakub Hrozek - 1.11.2-30Jakub Hrozek - 1.11.2-29Jakub Hrozek - 1.11.2-28Jakub Hrozek - 1.11.2-27Jakub Hrozek - 1.11.2-26Jakub Hrozek - 1.11.2-25Jakub Hrozek - 1.11.2-24Jakub Hrozek - 1.11.2-23Jakub Hrozek - 1.11.2-22Jakub Hrozek - 1.11.2-21Jakub Hrozek - 1.11.2-20Daniel Mach - 1.11.2-19Jakub Hrozek - 1.11.2-18Jakub Hrozek - 1.11.2-17Jakub Hrozek - 1.11.2-16Jakub Hrozek - 1.11.2-15Jakub Hrozek - 1.11.2-14Jakub Hrozek - 1.11.2-13Jakub Hrozek - 1.11.2-12Jakub Hrozek - 1.11.2-11Jakub Hrozek - 1.11.2-10Jakub Hrozek - 1.11.2-9Jakub Hrozek - 1.11.2-8Jakub Hrozek - 1.11.2-7Jakub Hrozek - 1.11.2-6Jakub Hrozek - 1.11.2-5Jakub Hrozek - 1.11.2-4Jakub Hrozek - 1.11.2-3Jakub Hrozek - 1.11.2-2Jakub Hrozek - 1.11.2-1Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-5Jakub Hrozek - 1.10.1-4Jakub Hrozek - 1.10.1-3Jakub Hrozek - 1.10.1-2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-18Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1899593 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() [rhel-7.9.z] - Resolves: rhbz#1888409 - sssd component logging is now too generic in syslog/journal [rhel-7.9.z] - Resolves: rhbz#1852659 - sssd service is starting even though it is disabled state [rhel-7.9.z] - Resolves: rhbz#1893443 - User lookups over the InfoPipe responder fail intermittently [rhel-7.9.z] - Resolves: rhbz#1871288 - krb5_child denies ssh users when pki device detected [rhel-7.9.z] - Resolves: rhbz#1853703 - Unexpected behavior and issue with filter_users/filter_groups option [rhel-7.9.z] - Resolves: rhbz#1756240 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains [rhel-7.9.z] - Resolves: rhbz#1851112 - LDAP bind can fail due to unconfigurable DNS server timeouts that inhibit SSSD failover [rhel-7.9.z]- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again)) - just bumping the version to build for proper target- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete (again))- Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] (Previous attempt to fix this issue was incomplete)- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z] - just bumping the version to build for proper target- Resolves: rhbz#1854317 - sssd crashes after last update to sssd-common-1.16.4-37.el7_8.1 with servers configured with multiple domains [rhel-7.9.z] - Resolves: rhbz#1859554 - Secondary LDAP group go missing from 'id' command on RHEL 7.8 with sssd-1.16.2-37.el7_8.1 [rhel-7.9.z]- Resolves: rhbz#1804005 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1773409 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1551077 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1507683 - GDM password prompt when cert mapped to multiple users and promptusername is False- Resolves: rhbz#1796873 - [sssd] RHEL 7.9 Tier 0 Localization- Resolves: rhbz#1553784 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1836910 - Rhel7.7 server have an issue regarding dyndns update for PTR-records which is done by sssd on active directory DNS servers. It is done in two steps (two different nsupdate messages).- Resolves: rhbz#1835813 - sssd boots offline if symlink for /etc/resolv.conf is broken/missing - Resolves: rhbz#1837545 - Users must be informed better when internal WATCHDOG terminates process.- Resolves: rhbz#1819013 - pam_sss reports PAM_CRED_ERR when providing wrong password for an existing IPA user, but this error's description is misleading - Resolves: rhbz#1800571 - Multiples Kerberos ticket on RHEL 7.7 after lock and unlock screen- Resolves: rhbz#1834266 - "off-by-one error" in watchdog implementation- Resolves: rhbz#1829806 - [Bug] Reduce logging about flat names - Resolves: rhbz#1800564 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package- Resolves: rhbz#1683946 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working setup- Resolves: rhbz#1513371 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_be[PROXY] killed by 6 - Resolves: rhbz#1568083 - subdomain lookup fails when certmaprule contains DN - Resolves: rhbz#1781539 - PKINIT with KCM does not work - Resolves: rhbz#1786341 - SSSD doesn't honour the customized ID view created in IPA - Resolves: rhbz#1709818 - override_gid did not work for subdomain. - Resolves: rhbz#1719718 - Validator warning issue : Attribute 'dns_resolver_op_timeout' is not allowed in section 'domain/REMOVED'. Check for typos - Resolves: rhbz#1787067 - sssd (sssd_be) is consuming 100 CPU, partially due to failing mem-cache - Resolves: rhbz#1822461 - background refresh task does not refresh updated netgroup entries - Added missing 'Requires' to resolves some of rpmdiff tool warnings- Resolves: rhbz#1796352 - Rebase SSSD for RHEL 7.9- Resolves: rhbz#1789349 - id command taking 1+ minute for returning user information - Also updates spec file to not replace /pam.d/sssd-shadowutils on update- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider - just bumping the version to fix generated dates in man pages- Resolves: rhbz#1784620 - Force LDAPS over 636 with AD Access Provider- Resolves: rhbz#1769755 - sssd failover leads to delayed and failed logins- Resolves: rhbz#1768404 - automount on RHEL7 gives the message 'lookup(sss): setautomntent: No such file or directory'- Resolves: rhbz#1734056 - [sssd] RHEL 7.8 Tier 0 Localization- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1746878 - Let IPA client read IPA objects via LDAP and not a extdom plugin when resolving trusted users and groups- Resolves: rhbz#1530741 - Trusted domain user logins succeed after using ipa trustdomain-disable- Resolves: rhbz#1713352 - Implicit files domain gets activated when no sssd.conf present and sssd is started- Resolves: rhbz#1206221 - sssd should not always read entire autofs map from ldap- Resolves: rhbz#1657978 - SSSD is not refreshing cached user data for the ipa sub-domain in a IPA/AD trust- Resolves: rhbz#1541172 - ad_enabled_domains does not disable old subdomain after a restart until a timer removes it- Resolves: rhbz#1738674 - Paging not enabled when fetching external groups, limits the number of external groups to 2000- Resolves: rhbz#1650018 - SSSD doesn't clear cache entries for IDs below min_id- Resolves: rhbz#1724088 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1422618 - sssd does not failover to another IPA server if just the KDC service fails - Just bumping the version to work around "build already exists"- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization - Rebuild japanese gmo file explicitly- Resolves: rhbz#1714952 - [sssd] RHEL 7.7 Tier 0 Localization- Resolves: rhbz#1707959 - sssd does not properly check GSS-SPNEGO- Resolves: rhbz#1710286 - The server error message is not returned if password change fails- Resolves: rhbz#1711832 - The files provider does not handle resetOffline properly- Resolves: rhbz#1707759 - Error accessing files on samba share randomly- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains /trusts- Resolves: rhbz#1684979 - The HBAC code requires dereference to be enabled and fails otherwise- Resolves: rhbz#1576524 - RHEL STIG pointing sssd Packaging issue - This was partially fixed by the rebase, but one spec file change was missing.- Resolves: rhbz#1524566 - FIPS mode breaks using pysss.so (sss_obfuscate)- Resolves: rhbz#1350012 - kinit / sssd kerberos fail over - Resolves: rhbz#720688 - [RFE] return multiple server addresses to the Kerberos locator plugin- Resolves: rhbz#1402056 - [RFE] Make 2FA prompting configurable- Resolves: rhbz#1666819 - SSSD can trigger a NSS lookup when parsing the filter_users/groups lists on startup, this can block the startup- Resolves: rhbz#1645461 - Slow ldb search causes blocking during startup which might cause the registration to time out- Resolves: rhbz#1685581 - Extend cached_auth_timeout to cover subdomains / trusts- Resolves: rhbz#1671138 - User is unable to perform sudo as a user on IPA Server, even though `sudo -l` shows permissions to do so- Resolves: rhbz#1657806 - [RFE]: Optionally disable generating auto private groups for subdomains of an AD provider- Resolves: rhbz#1641131 - [RFE] Need an option in SSSD so that it will skip GPOs that have groupPolicyContainers, unreadable by SSSD. - Resolves: rhbz#1660874 - CVE-2018-16838 sssd: improper implementation of GPOs due to too restrictive permissions [rhel-7]- Resolves: rhbz#1631656 - KCM: kinit: Matching credential not found while getting default ccache- Resolves: rhbz#1406678 - sssd service is starting before network service - Resolves: rhbz#1616853 - SSSD always boots in Offline mode- Resolves: rhbz#1658994 - Rebase SSSD to 1.16.x- Resolves: rhbz#1603311 - Enable generating user private groups only for users with uid == gid where gid does not correspond to a real LDAP group- Resolves: rhbz#1602172 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1622109 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1619706 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1593756 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: rhbz#1610667 - sssd_ssh leaks file descriptors when more than one certificate is converted into an SSH key - Resolves: rhbz#1583360 - The IPA selinux provider can return an error if SELinux is completely disabled- Resolves: rhbz#1602781 - Local users failed to login with same password- Resolves: rhbz#1586127 - Spurious check in the sssd nss memcache can cause the memory cache to be skipped- Resolves: rhbz#1522928 - sssd doesn't allow user with expired password- Resolves: rhbz#1607313 - When sssd is running as non-root user, the sudo pipe is created as sssd:sssd but then the private pipe ownership fails- Resolves: rhbz#1600822 - SSSD bails out saving desktop profiles in case an invalid profile is found- Resolves: rhbz#1582975 - The search filter for detecting POSIX attributes in global catalog is too broad and can cause a high load on the servers- Resolves: rhbz#1583725 - SSSD AD uses LDAP filter to detect POSIX attributes stored in AD GC also for regular AD DC queries - Resolves: rhbz#1416528 - sssd in cross realm trust configuration should be able to use AD KDCs from a client site defined in sssd.conf or a snippet - Resolves: rhbz#1592964 - Groups go missing with PAC enabled in sssd- Resolves: rhbz#1590603 - EMBARGOED CVE-2018-10852 sssd: information leak from the sssd-sudo responder [rhel-7] - Resolves: rhbz#1450778 - Full information regarding priority of lookup of principal in keytab not in man page- Resolves: rhbz#1494690 - kdcinfo files are not created for subdomains of a directly joined AD client - Resolves: rhbz#1583343 - Login with sshkeys stored in ipa not working after update to RHEL-7.5 - Resolves: rhbz#1527662 - Handle conflicting e-mail addresses more gracefully - Resolves: rhbz#1509691 - Document how to change the regular expression for SSSD so that group names with an @-sign can be parsed- Related: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch- Resolves: rhbz#1558498 - Rebase sssd to the latests upstream release of the 1.16 branch - Resolves: rhbz#1523019 - Reset password with two factor authentication fails - Resolves: rhbz#1534749 - Requesting an AD user's private group and then the user itself returns an emty homedir - Resolves: rhbz#1537272 - SSH public key authentication keeps working after keys are removed from ID view - Resolves: rhbz#1537279 - Certificate is not removed from cache when it's removed from the override - Resolves: rhbz#1562025 - externalUser sudo attribute must be fully-qualified - Resolves: rhbz#1577335 - /usr/libexec/sssd/sssd_autofs SIGABRT crash daily - Resolves: rhbz#1508530 - How should sudo behave without sudoHost attribute? - Resolves: rhbz#1546754 - The man page of sss_ssh_authorizedkeys can be enhanced to better explain how the keys are retrieved and how X.509 certificates can be used - Resolves: rhbz#1572790 - getgrgid/getpwuid fails in setups with multiple domains if the first domain uses mid_id/max_id - Resolves: rhbz#1561562 - sssd not honoring dyndns_server if the DNS update process is terminated with a signal - Resolves: rhbz#1583251 - home dir disappear in sssd cache on the IPA master for AD users - Resolves: rhbz#1514061 - ID override GID from Default Trust View is not properly resolved in case domain resolution order is set - Resolves: rhbz#1571466 - Utilizing domain_resolution_order in sssd.conf breaks SELinux user map - Resolves: rhbz#1571526 - SSSD with ID provider 'ad' should give a warning in case the ldap schema is manually changed to something different than 'ad'.- Resolves: rhbz#1547782 - The SSSD IPA provider allocates information about external groups on a long lived memory context, causing memory growth of the sssd_be process- Related: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1578291 - Samba can not register sss idmap module because it's using an outdated SMB_IDMAP_INTERFACE_VERSION- Resolves: rhbz#1516266 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1503802 - Smartcard authentication fails if SSSD is offline and 'krb5_store_password_if_offline = True' - Resolves: rhbz#1385665 - Incorrect error code returned from krb5_child (updated) - Resolves: rhbz#1547234 - SSSD's GPO code ignores ad_site option - Resolves: rhbz#1459348 - extend sss-certmap man page regarding priority processing - Resolves: rhbz#1220767 - Group renaming issue when "id_provider = ldap" is set - Resolves: rhbz#1538555 - crash in nss_protocol_fill_netgrent. sssd_nss[19234]: segfault at 80 ip 000055612688c2a0 sp 00007ffddf9b9cd0 error 4 in sssd_nss[55612687e000+39000]- Resolves: rhbz#1565774 - After updating to RHEL 7.5 failing to clear the sssd cache- Resolves: rhbz#1566782 - memory management issue in the sssd_nss_ex interface can cause the ns-slapd process on IPA server to crash- Related: rhbzrhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1543348 - sssd_be consumes more memory on RHEL 7.4 systems. - Resolves: rhbz#1544943 - sssd goes offline when renewing expired ticket- Resolves: rhbz#1523282 - sssd used wrong search base with wrong AD server- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Related: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7]- Resolves: rhbz#1517971 - AD Domain goes offline immediately during subdomain initialization - IPA AD Trust - Related: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Related: rhbz#1327705 - [RFE] Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1527149 - AD provider - AD BUILTIN groups are cached with gidNumber = 0 - Related: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1525644 - dbus-send unable to find user by CAC cert- Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card- Resolves: rhbz#1512027 - NSS by-id requests are not checked against max_id/min_id ranges before triggering the backend- Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Resolves: rhbz#1523010 - IPA user able to authenticate with revoked cert on smart card - Resolves: rhbz#1520984 - getent output is not showing home directory for IPA AD trusted user - Related: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1421194 - SSSD doesn't use AD global catalog for gidnumber lookup, resulting in unacceptable delay for large forests- Resolves: rhbz#1482231 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: rhbz#1512508 - SSSD fails to fetch group information after switching IPA client to a non-default view- Resolves: rhbz#1490120 - SSSD complaining about corrupted mmap cache and logging error in /var/log/messages and /var/log/sssd/sssd_nss.log- Resolves: rhbz#1272214 - [RFE] Create a local per system report about who can access that IDM client (attestation) - Resolves: rhbz#1482555 - sysdb index improvements - missing ghost attribute indexing, unneeded objectclass index etc.. - Resolves: rhbz#888739 - Enumerating large number of users makes sssd_be hog the cpu for a long time. - Resolves: rhbz#1373547 - SSSD performance issue with malloc and brk calls - Resolves: rhbz#1472255 - Improve SSSD performance in the 7.5 release- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1432010 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Related: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available- Resolves: rhbz#1507614 - Improve Smartcard integration if multiple certificates or multiple mapped identities are available - Related: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1408294 - SSSD authentication fails when two IPA accounts share an email address without a clear way to debug the problem - Resolves: rhbz#1502686 - crash - /usr/libexec/sssd/sssd_nss in nss_setnetgrent_timeout- Related: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Related: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1473571 - ipa-extdom-extop plugin can exhaust DS worker threads- Resolves: rhbz#1484376 - [RFE] Add a configuration option to SSSD to disable the memory cache - Resolves: rhbz#1327705 - Automatic creation of user private groups on RHEL clients joined to AD via sssd [RHEL 7] - Resolves: rhbz#1505277 - Race condition between refreshing the cr_domain list and a request that is using the list can cause a segfault is sssd_nss - Resolves: rhbz#1462343 - document information on why SSSD does not use host-based security filtering when processing AD GPOs - Resolves: rhbz#1498734 - sssd_be stuck in an infinite loop after completing full refresh of sudo rules - Resolves: rhbz#1400614 - [RFE] sssd should remember DNS sites from first search - Resolves: rhbz#1460724 - SYSLOG_IDENTIFIER is different - Resolves: rhbz#1459609 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds.- Resolves: rhbz#1469791 - Rebase SSSD to version 1.16+ - Resolves: rhbz#1132264 - Allow sssd to retrieve sudo rules of local users whose sudo rules stored in ldap server - Resolves: rhbz#1301740 - sssd can be marked offline if a trusted domain is not reachable - Resolves: rhbz#1399262 - Use TCP for kerberos with AD by default - Resolves: rhbz#1416150 - RFE: Log to syslog when sssd cannot contact servers, goes offline - Resolves: rhbz#1441908 - SELINUX: Use getseuserbyname to get IPA seuser - Resolves: rhbz#1454559 - python-sssdconfig doesn't parse hexadecimal debug _level, resulting in set_option(): /usr/lib/python2.7/site-packages/SSSDConfig/__init__.py killed by TypeError - Resolves: rhbz#1456968 - MAN: document that attribute 'provider' is not allowed in section 'secrets' - Resolves: rhbz#1460689 - KCM/secrets: Storing many secrets in a rapid succession segfaults the secrets responder - Resolves: rhbz#1464049 - Idle nss file descriptors should be closed - Resolves: rhbz#1468610 - sssd_be is utilizing more CPU during sudo rules refresh - Resolves: rhbz#1474711 - Querying the AD domain for external domain's ID can mark the AD domain offline - Resolves: rhbz#1479398 - samba shares with sssd authentication broken on 7.4 - Resolves: rhbz#1479983 - id root triggers an LDAP lookup - Resolves: rhbz#1489895 - Issues with certificate mapping rules - Resolves: rhbz#1490501 - sssd incorrectly checks 'try_inotify' thinking it is the wrong section - Resolves: rhbz#1490913 - MAN: Document that full_name_format must be set if the output of trusted domains user resolution should be shortnames only - Resolves: rhbz#1499659 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-7.5] - Resolves: rhbz#1461899 - Loading enterprise principals doesn't work with a primed cache - Resolves: rhbz#1482674 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: rhbz#1486053 - Accessing IdM kerberos ticket fails while id mapping is applied - Resolves: rhbz#1486786 - sssd going in offline mode due to sudo search filter. - Resolves: rhbz#1500087 - SSSD creates bad override search filter due to AD Trust object with parenthesis - Resolves: rhbz#1502713 - SSSD can crash due to ABI changes in libldb >= 1.2.0 (1.1.30) - Resolves: rhbz#1461462 - sssd_client: add mutex protected call to the PAC responder - Resolves: rhbz#1489666 - Combination sssd-ad and postfix recieve incorrect mail with asterisks or spaces - Resolves: rhbz#1525052 - sssd_krb5_localauth_plugin fails to fallback to otheri localname rules- Require the 7.5 libldb version which broke ABI - Related: rhbz#1469791 - Rebase SSSD to version 1.16+- Resolves: rhbz#1457926 - Wrong search base used when SSSD is directly connected to AD child domain- Resolves: rhbz#1450107 - SSSD doesn't handle conflicts between users from trusted domains with the same name when shortname user resolution is enabled- Resolves: rhbz#1459846 - krb5: properly handle 'password expired' information retured by the KDC during PKINIT/Smartcard authentication- Resolves: rhbz#1430415 - ldap_purge_cache_timeout in RHEL7.3 invalidate most of the entries once the cleanup task kicks in- Resolves: rhbz#1455254 - Make domain available as user attribute- Resolves: rhbz#1449731 - IPA client cannot change AD Trusted User password- Resolves: rhbz#1457927 - getent failed to fetch netgroup information after changing default_domain_suffix to ADdomin in /etc/sssd/sssd.conf- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15- Resolves: rhbz#1449728 - LDAP to IPA migration doesn't work in master- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1449729 - org.freedesktop.sssd.infopipe.GetUserGroups does not resolve groups into names with AD- Resolves: rhbz#1450094 - Properly support IPA's promptusername config option- Resolves: rhbz#1457644 - Segfault in access_provider = krb5 is set in sssd.conf due to an off-by-one error when constructing the child send buffer - Resolves: rhbz#1456531 - Option name typos are not detected with validator function of sssctl config-check command in domain sections- Resolves: rhbz#1428906 - sssd intermittently failing to resolve groups for an AD user in IPA-AD trust environment.- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail - Fix Coverity issues in patches for rhbz#1445445- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1446302 - crash in sssd-kcm due to a race-condition between two concurrent requests- Resolves: rhbz#1389796 - Smartcard authentication with UPN as logon name might fail- Resolves: rhbz#1306707 - Need better debug message when krb5_child returns an unhandled error, leading to a System Error PAM code- Resolves: rhbz#1446535 - Group resolution does not work in subdomain without ad_server option- Resolves: rhbz#1449726 - sss_nss_getlistbycert() does not return results from multiple domains - Resolves: rhbz#1447098 - sssd unable to search dbus for ipa user by certificate - Additional patch for rhbz#1440132- Reapply patch by Lukas Slebodnik to fix upgrade issues with libwbclient - Resolves: rhbz#1439457 - SSSD does not start after upgrade from 7.3 to 7.4 - Resolves: rhbz#1449107 - error: %pre(sssd-common-1.15.2-26.el7.x86_64) scriptlet failed, exit status 3- Resolves: rhbz#1440132 - fiter_users and filter_groups stop working properly in v 1.15 - Also apply an additional patch for rhbz#1441545- Resolves: rhbz#1445445 - Smart card login fails if same cert mapped to IdM user and AD user- Resolves: rhbz#1434992 - Wrong pam return code for user from subdomain with ad_access_filter- Resolves: rhbz#1430494 - expect sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy manuals to be packaged into sssd-common package- Resolves: rhbz#1427749 - SSSD in server mode iterates over all domains for group-by-GID requests, causing unnecessary searches- Resolves: rhbz#1446139 - Infopipe method ListByCertificate does not return the users with overrides- Resolves: rhbz#1441545 - With multiple subdomain sections id command output for user is not displayed for both domains- Resolves: rhbz#1428866 - Using ad_enabled_domains configuration option in sssd.conf causes nameservice lookups to fail.- Remove an unused variable from the sssd-secrets responder - Related: rhbz#1398701 - [sssd-secrets] https proxy talks plain http - Improve two DEBUG messages in the client trust code to aid troubleshooting - Fix standalone application domains - Related: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Allow completely server-side unqualified name resolution if the domain order is set, do not require any client-side changes - Related: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users- Resolves: rhbz#1402532 - D-Bus interface of sssd is giving inappropriate group information for trusted AD users- Resolves: rhbz#1431858 - Wrong principal found with ad provider and long host name- Resolves: rhbz#1415167 - pam_acct_mgmt with pam_sss.so fails in unprivileged container unless selinux_provider = none is used- Resolves: rhbz#1438388 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_pam killed by 6- Resolves: rhbz#1432112 - sssctl config-check does not give any error when default configuration file is not present- Resolves: rhbz#1438374 - [abrt] [faf] sssd: vfprintf(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1427195 - sssd_nss consumes more memory until restarted or machine swaps- Resolves: rhbz#1414023 - Create troubleshooting tool to determine if a failure is in SSSD or not when using layered products like RH-SSO/CFME etc- Resolves: rhbz#1398701 - [sssd-secrets] https proxy talks plain http- Fix off-by-one error in the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1425891 - Support delivering non-POSIX users and groups through the IFP and PAM interfaces- Resolves: rhbz#1434991 - Issue processing ssh keys from certificates in ssh respoder- Resolves: rhbz#1330196 - [RFE] Short name input format with SSSD for users from all domains when domain autodiscovery is used or when IPA client resolves trusted AD domain users - Also backport some buildtime fixes for the KCM responder - Related: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1396012 - [RFE] KCM ccache daemon in SSSD- Resolves: rhbz#1340711 - [RFE] Use one smartcard and certificate for authentication to distinct logon accounts- Update to upstream 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html - Resolves: rhbz#1418728 - IPA - sudo does not handle associated conflict entries - Resolves: rhbz#1386748 - sssd doesn't update PTR records if A/PTR zones are configured as non-secure and secure - Resolves: rhbz#1214491 - [RFE] Make it possible to configure AD subdomain in the SSSD server mode- Drop "NOUPSTREAM: Bundle http-parser" patch Related: rhbz#1393819 - New package: http-parser- Update to upstream 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html - Resolves: rhbz#1327085 - Don't prompt for password if there is already one on the stack - Resolves: rhbz#1378722 - [RFE] Make GETSIDBYNAME and GETORIGBYNAME request aware of UPNs and aliases - Resolves: rhbz#1405075 - [RFE] Add PKINIT support to SSSD Kerberos provider - Resolves: rhbz#1416526 - Need correction in sssd-krb5 man page - Resolves: rhbz#1418752 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1419356 - Fails to accept any sudo rules if there are two user entries in an ldap role with the same sudo user - Resolves: rhbz#1421622 - SSSD - Users/Groups are cached as mixed-case resulting in users unable to sign in- Fix several packaging issues, notably the p11_child is no longer setuid and the libwbclient used a wrong version number in the symlink- Update to upstream 1.15.0 - Resolves: rhbz#1393824 - Rebase SSSD to version 1.15 - Resolves: rhbz#1407960 - wbcLookupSid() fails in pdomain is NULL - Resolves: rhbz#1406437 - sssctl netgroup-show Cannot allocate memory - Resolves: rhbz#1400422 - Use-after free in resolver in case the fd is writeable and readable at the same time - Resolves: rhbz#1393085 - bz - ldap group names don't resolve after upgrading sssd to 1.14.0 if ldap_nesting_level is set to 0 - Resolves: rhbz#1392444 - sssd_be keeps crashing - Resolves: rhbz#1392441 - sssd fails to start after upgrading to RHEL 7.3 - Resolves: rhbz#1382602 - autofs map resolution doesn't work offline - Resolves: rhbz#1380436 - sudo: ignore case on case insensitive domains - Resolves: rhbz#1378251 - Typo In SSSD-AD Man Page - Resolves: rhbz#1373427 - Clock skew makes SSSD return System Error - Resolves: rhbz#1306707 - Need better handling of "Server not found in Kerberos database" - Resolves: rhbz#1297462 - Don't include 'enable_only=sssd' in the localauth plugin config- Resolves: rhbz#1382598 - IPA: Uninitialized variable during subdomain check- Resolves: rhbz#1378911 - No supplementary groups are resolved for users in nested OUs when domain stanza differs from AD domain- Resolves: rhbz#1372075 - AD provider: SSSD does not retrieve a domain-local group with the AD provider when following AGGUDLP group structure across domains- Resolves: rhbz#1376831 - sssd-common is missing dependency on sssd-sudo- Resolves: rhbz#1371631 - login using gdm calls for gdm-smartcard when smartcard authentication is not enabled- Resolves: rhbz#1373420 - sss_override fails to export- Resolves: rhbz#1375299 - sss_groupshow fails with error "No such group in local domain. Printing groups only allowed in local domain"- Resolves: rhbz#1375182 - SSSD goes offline when the LDAP server returns sizelimit exceeded- Resolves: rhbz#1372753 - Access denied for user when access_provider = krb5 is set in sssd.conf- Resolves: rhbz#1373444 - unable to create group in sssd cache - Resolves: rhbz#1373577 - unable to add local user in sssd to a group in sssd- Resolves: rhbz#1369118 - Don't enable the default shadowtils domain in RHEL- Fix permissions for the private pipe directory - Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1371977 - resolving IPA nested user groups is broken in 1.14- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1371152 - SSSD qualifies principal twice in IPA-AD trust if the principal attribute doesn't exist on the AD side- Apply forgotten patch - Resolves: rhbz#1368496 - sssd is not able to authenticate with alias - Resolves: rhbz#1366470 - sssd: throw away the timestamp cache if re-initializing the persistent cache - Fix deleting non-existent secret - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1362716 - selinux avc denial for vsftp login as ipa user- Resolves: rhbz#1368496 - sssd is not able to authenticate with alias- Resolves: rhbz#1364033 - sssd exits if clock is adjusted backwards after boot- Resolves: rhbz#1362023 - SSSD fails to start when ldap_user_extra_attrs contains mail- Resolves: rhbz#1368324 - libsss_autofs.so is packaged in two packages sssd-common and libsss_autofs- Fix RPM scriptlet plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Add socket-activation plumbing for the sssd-secrets responder - Related: rhbz#1311056 - Add a Secrets as a Service component- Own the secrets directory - Related: rhbz#1311056 - Add a Secrets as a Service component- Resolves: rhbz#1268874 - Add an option to disable checking for trusted domains in the subdomains provider- Resolves: rhbz#1271280 - sssd stores and returns incorrect information about empty netgroup (ldap-server: 389-ds)- Resolves: rhbz#1290500 - [feat] command to manually list fo_add_server_to_list information- Add several small fixes related to the config API - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Resolves: rhbz#1349900 - gpo search errors out and gpo_cache file is never created- Fix regressions in the simple access provider - Resolves: rhbz#1360806 - sssd does not start if sub-domain user is used with simple access provider - Apply a number of specfile patches to better match the upstream spefile - Related: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3- Cherry-pick patches from upstream that fix several regressions - Avoid checking local users in all cases - Resolves: rhbz#1353951 - sssd_pam leaks file descriptors- Resolves: rhbz#1364118 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_nss killed by 11 - Resolves: rhbz#1361563 - Wrong pam error code returned for password change in offline mode- Resolves: rhbz#1309745 - Support multiple principals for IPA users- Resolves: rhbz#1304992 - Handle overriden name of members in the memberUid attribute- handle unresolvable sites more gracefully - Resolves: rhbz#1346011 - sssd is looking at a server in the GC of a subdomain, not the root domain. - fix compilation warnings in unit tests- fix capaths output - Resolves: rhbz#1344940 - GSSAPI error causes failures for child domain user logins across IPA - AD trust - also fix Coverity issues in the secrets responder and suppress noisy debug messages when setting the timestamp cache- Resolves: rhbz#1356577 - sssctl: Time stamps without time zone information- Resolves: rhbz#1354414 - New or modified ID-View User overrides are not visible unless rm -f /var/lib/sss/db/*cache*- Resolves: rhbz#1211631 - [RFE] Support of UPN for IdM trusted domains- Resolves: rhbz#1350520 - [abrt] sssd-common: ipa_dyndns_update_send(): sssd_be killed by SIGSEGV- Resolves: rhbz#1349882 - sssd does not work under non-root user - Also cherry-pick a few patches from upstream to fix config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Sync a few minor patches from upstream - Fix sssctl manpage - Fix nss-tests unit test on big-endian machines - Fix several issues in the config schema - Related: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- Bundle http-parser - Resolves: rhbz#1311056 - Add a Secrets as a Service component- Sync a few minor patches from upstream - Fix a failover issue - Resolves: rhbz#1334749 - sssd fails to mark a connection as bad on searches that time out- Explicitly BuildRequire newer ding-libs - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check)- New upstream release 1.14.0 - Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#835492 - [RFE] SSSD admin tool request - force reload - Resolves: rhbz#1072458 - [RFE] SSSD configuration file test tool (sssd_check) - Resolves: rhbz#1278691 - Please fix rfc2307 autofs schema defaults - Resolves: rhbz#1287209 - default_domain_suffix Appended to User Name - Resolves: rhbz#1300663 - Improve sudo protocol to support configurations with default_domain_suffix - Resolves: rhbz#1312275 - Support authentication indicators from IPA- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - Resolves: rhbz#790113 - [RFE] "include" directive in sssd.conf - Resolves: rhbz#874985 - [RFE] AD provider support for automount lookups - Resolves: rhbz#879333 - [RFE] SSSD admin tool request - status overview - Resolves: rhbz#1140022 - [RFE]Allow sssd to add a new option that would specify which server to update DNS with - Resolves: rhbz#1290380 - RFE: Improve SSSD performance in large environments - Resolves: rhbz#883886 - sssd: incorrect checks on length values during packet decoding - Resolves: rhbz#988207 - sssd does not detail which line in configuration is invalid - Resolves: rhbz#1007969 - sssd_cache does not remove have an option to remove the sssd database - Resolves: rhbz#1103249 - PAC responder needs much time to process large group lists - Resolves: rhbz#1118257 - Users in ipa groups, added to netgroups are not resovable - Resolves: rhbz#1269018 - Too much logging from sssd_be - Resolves: rhbz#1293695 - sssd mixup nested group from AD trusted domains - Resolves: rhbz#1308935 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user - Resolves: rhbz#1315766 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo - Resolves: rhbz#1316164 - SSSD fails to process GPO from Active Directory - Resolves: rhbz#1322458 - sssd_be[11010]: segfault at 0 ip 00007ff889ff61bb sp 00007ffc7d66a3b0 error 4 in libsss_ipa.so[7ff889fcf000+5d000]- Resolves: rhbz#1290381 - Rebase SSSD to 1.14.x in RHEL-7.3 - The rebase includes fixes for the following bugzillas: - Resolves: rhbz#789477 - [RFE] SUDO: Support the IPA schema - Resolves: rhbz#1059972 - RFE: SSSD: Automatically assign new slices for any AD domain - Resolves: rhbz#1233200 - man sssd.conf should clarify details about subdomain_inherit option. - Resolves: rhbz#1238144 - Need better libhbac debuging added to sssd - Resolves: rhbz#1265366 - sss_override segfaults when accidentally adding --help flag to some commands - Resolves: rhbz#1269512 - sss_override: memory violation - Resolves: rhbz#1278566 - crash in sssd when non-Englsh locale is used and pam_strerror prints non-ASCII characters - Resolves: rhbz#1283686 - groups get deleted from the cache - Resolves: rhbz#1290378 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1292238 - extreme memory usage in libnfsidmap sss.so plug-in when resolving groups with many members - Resolves: rhbz#1292456 - sssd_be AD segfaults on missing A record - Resolves: rhbz#1294670 - Local users with local sudo rules causes LDAP queries - Resolves: rhbz#1296618 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1299553 - Cannot retrieve users after upgrade from 1.12 to 1.13 - Resolves: rhbz#1302821 - Cannot start sssd after switching to non-root - Resolves: rhbz#1310877 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs - Resolves: rhbz#1313014 - sssd is not closing sockets properly - Resolves: rhbz#1318996 - SSSD does not fail over to next GC - Resolves: rhbz#1327270 - local overrides: issues with sub-domain users and mixed case names - Resolves: rhbz#1342547 - sssd-libwbclient: wbcSidsToUnixIds should not fail on lookup errors- Build the PAC plugin with krb5-1.14 - Related: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1336688 - sssd tries to resolve global catalog servers from AD forest sub-domains in AD-IPA trust setup- Resolves: rhbz#1290853 - [sssd] Trusted (AD) user's info stays in sssd cache for much more than expected.- Resolves: rhbz#1336706 - sssd_nss memory usage keeps growing when trying to retrieve non-existing netgroups- Resolves: rhbz#1296902 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1334159 - IPA provider crashes if a netgroup from a trusted domain is requested- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin - More patches from upstream related to the memory leak- Resolves: rhbz#1308913 - sssd be memory leak in sssd's memberof plugin- Resolves: rhbz#1300740 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid- Resolves: rhbz#1284814 - sssd: [sysdb_add_user] (0x0400): Error: 17- Resolves: rhbz#1270827 - local overrides: don't contact server with overridden name/id- Resolves: rhbz#1267837 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- Resolves: rhbz#1267176 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1267836 - PAM responder crashed if user was not set- Resolves: rhbz#1266107 - AD: Conditional jump or move depends on uninitialised value- Resolves: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Fix a Coverity warning in dyndns code - Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1261155 - nsupdate exits on first GSSAPI error instead of processing other commands- Resolves: rhbz#1263735 - Could not resolve AD user from root domain- Remove -d from sss_override manpage - Related: rhbz#1259512 - sss_override : The local override user is not found- Patches required for better handling of failover with one-way trusts - Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1263587 - sss_override --name doesn't work with RFC2307 and ghost users- Resolves: rhbz#1259512 - sss_override : The local override user is not found- Resolves: rhbz#1260027 - sssd_be memory leak with sssd-ad in GPO code- Resolves: rhbz#1256398 - sssd cannot resolve user names containing backslash with ldap provider- Resolves: rhbz#1254189 - sss_override contains an extra parameter --debug but is not listed in the man page or in the arguments help- Resolves: rhbz#1254518 - Fix crash in nss responder- Support import/export for local overrides - Support FQDNs for local overrides - Resolves: rhbz#1254184 - sss_override does not work correctly when 'use_fully_qualified_names = True'- Resolves: rhbz#1244950 - Add index for 'objectSIDString' and maybe to other cache attributes- Resolves: rhbz#1250415 - sssd: p11_child hardening- Related: rhbz#1250135 - Detect re-established trusts in the IPA subdomain code- Resolves: rhbz#1202724 - [RFE] Add a way to lookup users based on CAC identity certificates- Resolves: rhbz#1232950 - [IPA/IdM] sudoOrder not honored as expected- Fix wildcard_limit=0 - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Fix race condition in invalidating the memory cache - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Resolves: rhbz#1249015 - KDC proxy not working with SSSD krb5_use_kdcinfo enabled- Bump release number - Related: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- Fix missing dependency of sssd-tools - Resolves: rhbz#1246489 - sss_obfuscate fails with "ImportError: No module named pysss"- More memory cache related fixes - Related: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Remove binary blob from SC patches as patch(1) can't handle those - Related: rhbz#854396 - [RFE] Support for smart cards- Resolves: rhbz#1244949 - getgrgid for user's UID on a trust client prevents getpw*- Fix memory cache integration tests - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#854396 - [RFE] Support for smart cards- Remove OTP from PAM stack correctly - Related: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Handle sssd-owned keytabs when sssd runs as root - Related: rhbz#1205144 - RFE: Support one-way trusts for IPA- Resolves: rhbz#1183747 - [FEAT] UID and GID mapping on individual clients- Resolves: rhbz#1206565 - [RFE] Add dualstack and multihomed support - Resolves: rhbz#1187146 - If v4 address exists, will not create nonexistant v6 in ipa domain- Resolves: rhbz#1242942 - well-known SID check is broken for NetBIOS prefixes- Resolves: rhbz#1234722 - sssd ad provider fails to start in rhel7.2- Add support for InfoPipe wildcard requests - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface- Also package the initgr memcache - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Rebase to 1.13.0 upstream - Related: rhbz#1205554 - Rebase SSSD to 1.13.x - Resolves: rhbz#910187 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1206575 - [RFE] The fast memory cache should cache initgroups- Don't default to SSSD user - Related: rhbz#1205554 - Rebase SSSD to 1.13.x- Related: rhbz#1205554 - Rebase SSSD to 1.13.x - GPO default should be permissve- Resolves: rhbz#1205554 - Rebase SSSD to 1.13.x - Relax the libldb requirement - Resolves: rhbz#1221992 - sssd_be segfault at 0 ip sp error 6 in libtevent.so.0.9.21 - Resolves: rhbz#1221839 - SSSD group enumeration inconsistent due to binary SIDs - Resolves: rhbz#1219285 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust - Resolves: rhbz#1217559 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1217350 - ignore_group_members doesn't work for subdomains - Resolves: rhbz#1217127 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1216285 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set - Resolves: rhbz#1214719 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1214718 - Overridde with --login fails trusted adusers group membership resolution - Resolves: rhbz#1214716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1214337 - Overrides with --login work in second attempt - Resolves: rhbz#1212489 - Disable the cleanup task by default - Resolves: rhbz#1211830 - external users do not resolve with "default_domain_suffix" set in IPA server sssd.conf - Resolves: rhbz#1210854 - Only set the selinux context if the context differs from the local one - Resolves: rhbz#1209483 - When using id_provider=proxy with auth_provider=ldap, it does not work as expected - Resolves: rhbz#1209374 - Man sssd-ad(5) lists Group Policy Management Editor naming for some policies but not for all - Resolves: rhbz#1208507 - sysdb sudo search doesn't escape special characters - Resolves: rhbz#1206571 - [RFE] Expose D-BUS interface - Resolves: rhbz#1206566 - SSSD does not update Dynamic DNS records if the IPA domain differs from machine hostname's domain - Resolves: rhbz#1206189 - [bug] sssd always appends default_domain_suffix when checking for host keys - Resolves: rhbz#1204203 - sssd crashes intermittently - Resolves: rhbz#1203945 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default - Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only - Resolves: rhbz#1202245 - SSSD's HBAC processing is not permissive enough with broken replication entries - Resolves: rhbz#1201271 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything - Resolves: rhbz#1200873 - [RFE] Allow smart multi step prompting when user logs in with password and token code from IPA - Resolves: rhbz#1199541 - Read and use the TTL value when resolving a SRV query - Resolves: rhbz#1199533 - [RFE] Implement background refresh for users, groups or other cache objects - Resolves: rhbz#1199445 - Does sssd-ad use the most suitable attribute for group name? - Resolves: rhbz#1198477 - ccname_file_dummy is not unlinked on error - Resolves: rhbz#1187103 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1185536 - In ipa-ad trust, with 'default_domain_suffix' set to AD domain, IPA user are not able to log unless use_fully_qualified_names is set - Resolves: rhbz#1175760 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires - Resolves: rhbz#1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1205160 - Complain loudly if backend doesn't start due to missing or invalid keytab- Resolves: rhbz#1226119 - Properly handle AD's binary objectGUID- Filter out domain-local groups during AD initgroups operation - Related: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Resolves: rhbz#1201840 - SSSD downloads too much information when fetching information about groups- Initialize variable in the views code in one success and one failure path - Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Resolves: rhbz#1202170 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605- Handle case where there is no default and no rules - Resolves: rhbz#1192314 - With empty ipaselinuxusermapdefault security context on client is staff_u- Set a pointer in ldap_child to NULL to avoid warnings - Related: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1199143 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198759 - ccname_file_dummy is not unlinked on error- Run the restart in sssd-common posttrans - Explicitly require libwbclient - Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade- Fix endianess bug in fill_id() - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1187192 - IPA initgroups don't work correctly in non-default view- Resolves: rhbz#1184982 - Need to set different umask in selinux_child- Bump the release number - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Add a patch dependency - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Process ghost members only once - Fix processing of universal groups with members from different domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved- Handle GID override in MPG domains - Handle views with mixed-case domains - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Open socket to the PAC responder in krb5_child before dropping root - Related: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1184140 - Users saved throug extop don't have the originalMemberOf attribute- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD- Resolves: rhbz#889206 - On clock skew sssd returns system error- Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1177140 - gpo_child fails if "log level" is enabled in smb.conf - Related: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Resolves: rhbz#1171215 - Crash in function get_object_from_cache - Resolves: rhbz#1171383 - getent fails for posix group with AD users after login - Resolves: rhbz#1171382 - getent of AD universal group fails after group users login - Resolves: rhbz#1170300 - Access is not rejected for disabled domain - Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode - Resolves: rhbz#1168904 - gid is overridden by uid in default trust view- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear - Related: rhbz#1113783 - sssd should run under unprivileged user- Rebuild to add several forgotten Patch entries - Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Remove Coverity warnings in krb5_child code - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users - Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=- Don't error out on chpass with OTPs - Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users - Enable running unit tests without cmocka - Related: rhbz#1113783 - sssd should run under unprivileged user- krb5_child and ldap_child do not call Kerberos calls as root - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware- Fix typo in libwbclient-devel alternatives invocation - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.- Handle migrating clients between views - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Use alternatives for libwbclient - Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression- Add an option that describes where to put generated krb5 files to - Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12- Handle IPA group names returned from the extop plugin - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header- Resolves: rhbz#1163742 - "debug_timestamps = false" and "debug_microseconds = true" do not work after enabling journald with sssd.- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete- Support views for IPA users - Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Update man page to clarify TGs should be disabled with a custom search base - Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Use upstreamed patches for the rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1162480 - dereferencing failure against openldap server- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue - Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1113783 - sssd should run under unprivileged user- Fix two regressions in the new selinux_child process - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used- Include the ldap_child and selinux_child patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Support overriding SSH public keys with views - Support extended attributes via the extop plugin - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving - Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times- Include the responder and packaging patches for rootless sssd - Related: rhbz#1113783 - sssd should run under unprivileged user- Amend the sssd-ldap man page with info about lockout setup - Related: rhbz#1109756 - Rebase SSSD to 1.12 - Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server - Related: rhbz#1109756 - Rebase SSSD to 1.12- Add the low-level server changes for running as unprivileged user - Package the libsss_semange library needed for SELinux label changes - Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Use libsemanage for SELinux label changes - Resolves: rhbz#1113784 - sssd should audit selinux user map changes- Rebase SSSD to 1.12.2 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Sync with upstream - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebuild against ding-libs with fixed SONAME - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.1 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Require ldb 2.1.17 - Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer- Fix fully qualified IFP lookups - Related: rhbz#1109756 - Rebase SSSD to 1.12- Rebase SSSD to 1.12.0 - Related: rhbz#1109756 - Rebase SSSD to 1.12- Squash in upstream review comments about the PAC patch - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Backport a patch to allow krb5-utils-test to run as root - Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder- Fix a DEBUG message, backport two related fixes - Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success- Resolves: rhbz#1078840 - Error during password change- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider- Fix idmap documentation - Bump idmap version info - Related: rhbz#1067361 - Check IPA idranges before saving them to the cache- Pull some follow up man page fixes from upstream - Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes - Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks- Resolves: rhbz#1068640 - 'IPA: Don't call tevent_req_post outside _send' should be added to RHEL7- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does. - Use the right domain for AD site resolution - Related: rhbz#743503 - [RFE] sssd should support DNS sites- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin- Mass rebuild 2014-01-24- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn't exclude uidNumber in filter- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed. - Fix a typo in the man page - Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn't match any configured idmap domain - Fix return value when searching for AD domain flat names - Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\user- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20- Resolves: rhbz#1033133 - "System Error" when invalid ad_access_filter is used- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword. - Fix two memory leaks in the PAC responder (Related: rhbz#991065)- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup- Resolves: rhbz#1049533 - Group membership lookup issue- Mass rebuild 2013-12-27- Resolves: rhbz#894068 - sss_cache doesn't support subdomains- Re-initialize subdomains after provider startup - Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- The AD provider is able to resolve group memberships for groups with Global and Universal scope - Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog - Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested- Resolves: rhbz#1023409 - Valgrind sssd "Syscall param socketcall.sendto(msg) points to uninitialised byte(s)"- Resolves: rhbz#1037936 - sssd_be crashes occasionally- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb- Resolves: rhbz#1036157 - sssd can't retrieve auto.master when using the "default_domain_suffix" option in- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- Skip netgroups that don't provide well-formed triplets - Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2 - Resolves: rhbz#991065- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash - Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1 - Resolves: rhbz#991065 - Rebase SSSD to 1.11.0- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0 - Resolves: rhbz#991065- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2 - Related: rhbz#991065- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log- Resolves: #983580 - Netgroups should ignore the 'use_fully_qualified_names' setting- Apply several important fixes from upstream 1.10 branch - Related: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- Remove libcmocka dependency- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Enable hardened build for RHEL7- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/shsvuk1.16.5-10.el7_9.61.16.5-10.el7_9.6libsss_ipa.soselinux_childsssd-ipa-1.16.5COPYINGsssd-ipa.5.gzsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ipa-1.16.5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnuELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c8ab6adfae24502e6fc5ed2280fe91b1e550fde8, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID[sha1]=dc3d24d00eae98289193f784c6b48a0efa17d152, strippeddirectoryASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, from Unix, max compression)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, from Unix, max compression)FFPR"RRR R%RRRIRRFR/R RRRRRR?R!RR#R$R2RARRR@RRRR RCR1R,RR R3RGR)RRR0R R8R9R;R7R6R'R(R+R*R&R.R R:RHRRRR>RBRERV sʑ p/SsGD7BSM6JorꡛmjB\( -yܐhQ$K;4,0 1ֹ,silŸx|[%P@]YF0/0-nhBdWlIl5]A M9Y7$= X]%ݑ$͂6:JVb9 BB>n觗%!ompX}J֩DN ݋g}D?n&C՟,}]ԇTmJnCH1atHSͿ?Q<'9; e$n?̅\<鎑s6N~}JY߉0ȠF}pbڬ/iR:A ilK%Z,MID |OrJAqR6E(Y0dk}DOB&`DcIӫ"{m%FҲdb:!ְ~&Y&x8V6?(Nݴ^Y"" hG2u@iznzmd7pݬbSaҝd҉N+9\FlvDqe\u6||]̬<Ӝe8nM+Yq8(lq|^oKܿ0ճQSg*+YG8wNJ UJ$cK>"PB:B Iyڔ֩-o &xw otw Xb%%jJ*ԥ2iz]׵*&mWX/{P%c2r*CqJ;ls}9 K2>=#j$A{]4gw1Jw̗yt}PބӨNvqIz/ZF.RR9/I$~6hDP)y@L"/B~ Dpb/{$VOwaա40T 636|үxoUCaq/UFҭ&%( 9bq qf*ZhHN(ɐ^(H5:^ qXfn_MMI8 l; 1z8GᖥUc1|zr<~tun.QV>x/ [ D)ArAep^=oC=@], e3- ;s!ˮAÉͿG;LקhBad'qѠú&7UGc Dǩl4a .]4zƵ/z-u8(;` XB옎1.>6 bl?"3!ee7WDͺ>F +UƸMTwI##EB "86 `tuY[Jpe_3j&L٠.mPPU152upƨqAO&Eey? +p:D(߳v'{֬ٳQɟԌWhL9<4rAVLK.E}2k). 4.ۧuyB{yZwEڕ i{gCu6̭|EKNq}V 9leSQY5C PĘ3Z96S@y#, KpBn<|/ܒIb[&q9dUrx@i:BNޡBi[[459l/=80WdUmf ܝ)h^EN'LݷRhOlj.\ΘӲ+Gwl+Y4Kd~8 j%WNF|^ E?q rm6ɥDԏU2!פHۓn~E j5kM n;ҍ%;&zs ¦Eݰj8 ( d|X/1_;$ԥ%َȟ3huVnQuO%Zg)TP~`MoK g4hȱ5cβ"~(5mAl,vVgu- rogʔ: 5_fqwl8,ڦ߾4C;&2]DaZr XCU+ x+8r,p~8? p6(!2;nH O B'DLSǷ;_l4q\nWp JAb93 B@p~2U XM oqOf>͢"NPnFhu24WX*7@ $+Drآ7DB(;u HɑH蜚l75u蒹.>v&48lۻ^a2h$_ovJ4+-J}irP؞Z p%G5((a(t$%.qYo2{XXśbe,(`e4QBHBhm6_Fݬ2d\qK եY/Hvh1ѼJ$;1ҷCĻc#E_,BϪnOIꖉlo!%v00[)1..SL_L۲執yrFkh|h$3ux4@jw~PMڅuYUIw;1Elxm5nkܾ>rY7w~MS#&]quAfWf˘>9[m@O|O{U &tqX#fp0fK0V/ʭ,DC"yſ*(c*k96Ntfi3̟t"i2a}W֎O݇3f9"\PsV 06ܳ=-ѝDGuuw-7'tvSP'ٮo9K8fb 3pI6,T"D);50 tkc)u,w*vlXs~gQwpHulnn;6: 3i j8x6ԛ6i4Uo?Cu {e}YQ2`VdZWXb;[b@%NJ Y wd,CjAg_Lem|e8XC=9`'h9TA26BB$HFjA6E'1Pj_j Tr5li/ M-y0-N|f"iD࢕a!2[8kW73rvd{C|<Ǟ@{2 {2qYcyr^I 4f9H?OJj,j)ò*JTxRO窳l6'ٮRiG< xw-u#83 B-g/ESsQ XvǸ3?`.1;]PS$P`!K8X%"!iΫ x0i0Qԑ,_6ifΚ4\!$X(?xt: ;ly'f1\2 >G7}3:E=7 UFc.5ΙiA7螮ZbA+ ^z$@TIo*zOD1~ O.:xnVa'>m:8~1gY;'+.M6bb(]8tf34f rSeQGP90׿f}8G#ͲX\%U2|Yk1_+*KbLݻeL/lj/{ma ޘ& @z' 2DB7cJmԐPh+KԞ+F,% w" cǫ ,K4V.4ea˲vCNSH{@a_.""~#!3?2MG,hk4ѽiSAk¾a"tHFJ.WgHwpEO|gTgs3C7Lb,@G1hg%p?  % zdjͻ #*L#6Wxuj8YǷ*Exv f׎!UFf߇ e(>Hw /Z󫡮'*_y}%;o<\<ckx|5/ɵKd CU[Q^T.9Ă2KQ٩ c.<Kqt߭0 h`kwR[4y: -Agj.]$vgf7Kh/8 *_jh1%Bn^`~.uwXӻmK^zT|jB''\LQGt\Mnsp _Y 딴>"Ѧ``.K?OX"F<3T:8IiÚx5ʮ#2d>0qZE.-AGK{DRMu:E{/Fv%A|#;˖})WK}m;Òt ^_ϑg˖!h߳&Ȓ_!bhuY^nK#'*"7r^mkE(IeI\Ր[Bb5?v89U#jup:=9 Ry KV-]BQBr!.0Eu^C9e/2b~X|]C jR6KℂT uUFד%6b_, 3ȉC48ʤ] =(`Kct;A&G1l(Z͑jf{{4l}6cF|y{DfwiցQh]J@ `_oFgъ#-'ly(NHydJ-ŕRX"kzF]% 5| 0h8RXmY4 VyF^2!22H6A]% * sB.Xu.gNOظ%W+XjP&a uLz!3>ۤ] H"ItGK{x t !7'QI*Z]v.;̼1"GLPajt#}pʣkan,R ;uz;7,-rNϺ> pK\< hg:~껤07Q-\F|z!@~%b*kB}{k {=n"4+H#?ߖ9#F %vhmN zB]fKX )eT.-?G4 F)4zo1_2!`Ӥ d5%)y47:W5}ewU:yA=(9/hc=,r7B\\/dżn@+U"=+kwYa|b39>!|  A.psnpc / N.2%;|#/f$x-kP?N bXDc R)(UL1I 2NTr?Hʃ(dDhznb?)V@_o9+ٽjmu`;ÒʱcPIR! K{|nNG4 ^|>æڹOQY'WQrKgo'{yk{Ǣ,≭ߣeibʳ8'X#&ÙL{ ; g}'ZqT(@b4ˤ,TOMԶ {+ҪṮn6/FעN#O*UPND٪Lѯ{L4wh SqvKym4rxhuII<5?*Ԛt.^g^30h34P2B|҂=,no*j؛g8,h?;f0DJ>wxಙ y E.t .4@DVt80 (}!lM2{U;ehoY_MvHФg f6mD[K P5!"|${a_m5@ۥ)&*I 5E>r|j'" L-XbK)(gV\R7Z\W_iHr7o/())ӹ!Z?"CCSu13.|#)GIP~0Dܔ^&z0RI=5x2m~Mޑ -/^u2dѰ=IV!j#AwZ٤YsQoM7~9cq)4Wa-wfd"=,+*fAef VԴR^簟J'XUNpgyu>JfO*gN;]RlaE>BŸ}JӅEǩh;s{Mo}]Ę"@3`[*Uܱ l.Dy!ʚ·sru {=wSCYLsqVbqŖ&Pq.IgO&IaG#_[A-Qk4K.WOd~?H5;( %-3?<,"s@Mf@-m\aN> D5Ⱦ†!AHwbC7<{_xKqTc^2 V.GM?whV RyQE"]G̫zO><:g^m*Bj2 ㇇k~Εv.@v4􀿫(gsm, TҧmEFFDvWԄ7viQ^P+xgeIaK{@˩Xz}4B, 1J٦o ó ڻ]szPg`øbz GPk~vXhMç- -ʊ(? %)yQppEYWH=d !Á@ٝ JN!:ZT3UHs$€>-!β& ј| U\SnoX <9ل>fd@"ıɳ$j{WwtA}Jb>NC6=po>Wb%r砧]+ñemc DK8 쎰2يguHJMܔ7a%Yú w[1HJbk[b:`0 Tg0ʲ_Ѳ+UV%T*Kqsz\.{p<|ZkwKUSSHõrB`$A>mq,NЙ *xTZZ0ms[x0zUDBŸK7TV:BOc"|z*A.~ӛ{LDP%И/{g@`n ٩26']z˺nx׾IxYbtZ;qkĬ#YE5BD8Eз%CΨōIKxEz#:KP|u 639 5ohJjW z}Ը  n+ͷk]w=ꄶܜ)e\㶛`N)Y&HDZBj w[A nC)?O*:i-!NxҠK&])(Y{k&RѠGc|/sQe^JTE/04ۙU6g"q1d|@jrL6|:gTE+nutG *C^gUĈnEqk5>c^^j+3YU}@D&.͙,sVխ!HodY`8|mば>d&zM>O=iJ:;-ouCU] zIa]]i|Yq=M y9P\4mu..pV;崦A!o2t8}e Ȁ["޳71eT9@O<|,v9K}쉜&LЬ3xe9/~p۔|wM >w?) sDMȬҁ4/,v-n{t| GbR5]KiNFw/6xш#!8^Oi YH!̧x2 g @l ƽJ.  azk_/h G 7ٔu5n>aq޷R.y}/?uVu[D/Z)|ѪHZjunoTT# @&pziUB\0\+f1 qOW/e Eo!J~O%#ʚc}(W+߾ݡ4D}ǥ(PsOg>S#qusgsCLĥ㯘\*Wlʎ8MXr`;COK!"vrX.k*ws܍j7e40ȧbU5ʙ); Tr,FI5zץg=`RG [>2.oj*ɉol,%J]dpH*b]Dew|Nol\.zBD ipJUD6bGzD\y&,vQ;t 3}\^uP"֡e&-gˊKǻɧIT)e0tvw G  _5;HELE^R죮=im(t o3kvGxR/*OpUW7TߣLjMesf-N>DwEJN pRI 8>cׅSH +l|pN?YrnTZUjT &:=:=Dugk׉3Ok/H/in;gV_9T$*l82vKv`N 7])N8w_֗|ט,CHL޲:#9ǏdܶI}KX N61B.!%KI0nbCA6?)QJh)_.DO5 |6iB "0B OX4~2l r !$B߇q)Z/i `y]s`B9kaL Lo?r"?r3C v-(cBF,x"AXKXDV-kr02r#J"u !ñ7;.+jMmdϬ\ۉUdE4^"y2^LGyP,\[P 6|i+bf_8RD'tёW'nL.O=ZJ[YW2v"kzqk:BՁ[m졉I6+&,ՕjkXAO`\ ,AF:\l~񥗽 ArApwGOB̯xVÂhQgVO}7hʘ Q9͇*1٣Kb^hΩ1򣴡nsEFiŇJLv /ǡ$p ^/oÆrFZ!b-c{63He| :! i\zn5 AHxׄ!M杞%t Z8OdƏw +nj0O'۱W(×uWUg; ~|xfB)MH|rf{GmUC '>eϼΡWmN;Dzk IG+_ rc~ӉT.0W>% ےg3D.^ӳHať0jzu"YWH}.DOA"<{.z8=&BXKD>+'WS:TrܖFdwu`:PA}~0e1h@XGT(qZ+02瞺xJl(c^]>Lw51'&YPUe)< VCh9ހg)} *jSq* HR8(!AȫDt ;?OjJP]Ew%C7m| إl}L<0gONM2{LeMGD|(iPb Uo~&/D'QUd|esxOmJ.&u щ)RݤLIITT}}ϥ HzL󓳪VkX@9Jsg9J{t (&+g~]BzXZ3*1U}3ZYq P9Fɤn. 8C}zW]^5QUR,hyQlCECa̻$䬅 msYh}4(. vCсklܾ*ߤ@&BU`c{MGwbSY.Ϛ{ 뤗՚ٞ%>dx~'89ݺ旝򋛎^)~] }$ ^<¢|Љ@/Fj %|m a\J6WWhꖹ# ڦ}O!! ]z\1Zkc7zu\É0fFnRuQ;hlԞ‰dm7,Z0 HX,].!g!_kf(X~rIkkYtR@iG1Q)߬ ݂6nr 6m[Lm41tV3ѝ(ƌ"\=  WƁÅTnO8t='ɘae!" /xuG,~_}}lܝH1~+U*R?1d - $h&^}><=}.~ZQzFWA,R1.2A֦R}R)̉9tDED½XXkؖ'NôcU5Ħ-ܵL0ΩzLhSW t HkufI!k*BRP0iyQέ^+& jGG{(tN@>La)>6:ua8X.d#N+;AKvDai{}S2SIyMwie Eե%qCΦմY]ݰDk#bNC|S!_",Hqn%<0Z9wڿX:5Q Q 0EkCW&q4J!]:zASO76P51DYYa*כ2Lw VbMʚ_A޿T\ \$)jzTJD7~bsזz,ݲXN*3?> ѕ`Z6Kh̹0&p=FCD k ^=K~ۭSߤ"^C4_w;_v-3s@MoP :[LUֱ~Z3iW~O\>k@C5j|q/I e:/cM @_(A )ɔP ftJNܰ3hJD 8氙l 2XhB\ ի[,NfK/`Ȯ2Yb8ؓHLHI7o RN[Z[\.Y*lwYپzw3[O< @ܛh,l5 i'0(*|!3c'd#Rˠ *B`t? .^]~#I^?ԍ3@k.i4B acbq>a Gf͍ؕ!ȝiamfmwT(RI\GYh`:C/cg\*ctI/*r+d˷Czl5ŁD,҆We\"Q)u0rZh^j7ٟ^f84 =j` jy_EwnY-sm,e<ǿ/Qesu`5U)QG":-My`*0/%Fe-ޱ|C󶊢x8ؖ;(oScDm; 38(KΓ+CA#û;5 i[9o 7ͭzh\ʖkW Q\,[ƛ7FE[Z o~TLGL GW$#?`sTY94ٝ}7<៦"RV8{P-A˺NL-.>SK)M cGj[PhIB[ҜnY@/YoN̢r`۷?Q=Ƚu h2:vk򗻉]ź\#SO(SQYiC _ې: g'^ۂ0Ә&#H#))lbU4GgP< % ݂? eC); 3UFf+a/` ߨ-!غ&x#kh7Ƹ{F(3mam7p ?  -E|J!Ť=ktO떂34/'=QQGnյx37||%&X+,V /TE,ߟC#d tqQ9"}2\ugc-+5i ߾a0PO+ЌQ[`˃}pe S&ZӰ0"ވ?7h1@,e9V5F%2biC~ ~9 TGBF * IQ΢i ƒDNfW l"DiP^&^)K]GlLR#O.ʥA=smfcCQ!0Li>3܃r1qQ)nu*c^[,y;+5-dNuk K~Pv#U/it)4VF+P}E'Ӣbe:84*p{Pyپz($PyoE 齬-Bv3H-<2D]{NH2 r4Ta[su j(/ptΝkK&?fЉ7d?57H>DIy`6^D4ޕ&Q#< Z{ٰ@8gs&MuyfB貇 ~YZv(elEo3's3[D}"w[0T"w[.fΧ{1\+86ٻ;"Ip%h}Q+Xa`G͉7&@KseT4/} νLDF ?o$ڇ˄# |"uF/m@13 F5>ܶ^Ξ10c) `!=\؈6 d"JEH @ݿAM=-ewJBt3:/u$@a 鄿:Ți0 #7XerFN\`Oy`ӄsDB-w7!bOzvRjsV ɼ=4rd]%n୤rvmtǽ}`^I/-f؇?+r\NV}rVvhёo_ [ ^ܓ| od}~ֺhy߮Ra[HA213Cب116 @v *ߌr>:>"h8U K6tGrK14L։њ*4ygNFsm :i F;a&r_/}`ɵإ0(TVO"`&֖  $4@hxKX^ BElCP6+RUu$/#VNܧ(a'*W[ NZkޗW b`:9}l i6u-n}՞b6A%ڴP&NHMeo7 VM3V">y?Y90WkcSaANEp@RWH0'retV έ5PHû?t^0/UƱ6Xn17@vr݊ x uSc+fdRf{(~ME*xcVTH=d#S 3ռ. ;^C瓁`E1Z2@䰰jd pAIhRR& _&h*)c| բ-TM[ &rR>V!/磰'x>#;w~#0 ɞuDb. S@k }IvogŰLQWl z½DѼ{b6omTb#?XN8!k*:{B?ˣ3pR5^"ݟMhE= p:?Q5@T#0][yۄ* MqRLDW_¨FzH\ /k->'"0NE ]Rx;w^6/)u05 d aݖ8{*\EeW͙15%̻hsw,ܖ<DO˕zV}+ 袱]C_9F~G_-ةބgj0iR,}wxIx_H#mc uN0(\@h-sȜV@^3Vcϛ(chX 1}ÛlA}^[}4D u6u_tNH?<̛3ǥVq&XYJZ!%:w^5`ۚ#˯C羙[R2bWW h+f(^XjKghZ[5c u00UHh&33#|bT@Y=é ' !h'gƦWlL {0hTu1Գ+ †k `W(*h~ DD=hȶ\lQg0P{X6_Gf/U]jS4l"1iP_X).R:%%=7-|`M$ F51;f(=kteَrB7 4"Pq8Ų(-Hn⋤oqmKDDޝvNCЈW^,*z,z qK*r>0٤l/|\}'g0:3&enEP s|S49>tm)*)SĵaxgaPP:tmtEycSA̡q)3 r|d_Ր/@Zv4oC'n K"tSd m4.4^4j*K/-%dž\*ď&{C~AYvd)Mz#ѯJYeݟ=Zx8g*B6|}4*::gp~b]IE"I@^ҙ+"H5GE{Yrs/ޮhMH&Vw)'ˆJ([ d*pq 9]DN|bJ!`Bl“ʋDžԇHUD$w&Z;Zg+p 6VBΡ-ٜK2ŦNd*]((Xi;n;X E54ʴVz%[beglΏ}˨~åb]7gmtx$^*e9.dCP%S V:9k co=8[öGV"5>`yWMrnۡ{e}EP~KEq˾# hA%U:r-lq= 3{CHWLUIgWPHc51ْ^s1$\24i^(R;yBESw~v?hRb[>Vm j&i$a^i-ւb:f~j(M9/T06\t|:Ib:~:˽Tٹ܍K5 %/e<lj[>k%,qB^ PxH l})E5l6䃂;j=s㋭O9E'A/M:GĈf,ڷ=C$ G[;dA (zYUKKxϤ91;&7YC=yX*>ֆ|>RW,-C\.ՆҨ%JLQ w蛒pLoﮭNc]?睐yw1#rzժLzS];-N._IV[+haF/]4XkiHq`-Lrtv,zI_Io3שsi:"ǫؘnD;T55\86!~A0ns6y|H2rH7MV[UGVGAhdӖ3G%f"3]xH;4GK(#^x# C&Uy I~^,6HTmkIII=2sOY/ >cӕZձT. έ"F EFw}Ol^hVC{ܟN4k )UfDY\dwGu:sm,%j4X,Ҙ)hR)*2ZxkZ%gE҂}#k_-ϵ`.,+qQaF䉢3k:j˾RmFPF_INPxb֣NM06}x6+K&:PGX1O!2nU6|aRCTh PȔ5mP}P>NYu͒ KrC͋ KD&(̝l&N|9/bVigj'kdJPujsNy{ʆYB7XABHil\ѻ1%D7vXkӯ]Z箈>OdJHD tU@ũZP^c3Ӝ41g<`Uq(brt{yLӪl"Iaz.ZLP m1~9?8Ό]t70_>T'q" Pʷ}aʾM51bWt 3 ulъB*L9~ϚRt5"64/1ЦE@avz^h<_nZ  mYv┄\ud*h`X _=?pd]Wʖ[bN[ C.JQ\<ԛ e,4O'^'<8]ٓRVrr=vj+yNR,"t$h|m˥oG0]lˊ3xX>џl"Y] v5Dlߗ@<3 Ϧ:jMIǪW1B7ZwtM-&,{Z_Y&rzhnRX)DqMA nqq82d>֖q'$pu滐-i)1ݿI(‡2q(-9U@4S[RS~bٝ;-ȶkh;1j7vha^Eh:lgL?ޅ, =lTŌY%(B*@?KדLPa|f@9ƾeOc޹(crT'NbG5aKC^u$iqw:Kg[b^(7Js3FyEu468f۝UGxׅ"#/%Qzc^9 z%gCr /9Ka_P\$ӷ1BbfHYCH:*kğONPxMPZ-9U@߳`qejtQgѹZ*JG~P|&f :M$Fsќ)0ɳr˩ h{EcF VeO /2 x7u /OՌ]Nc\0T!u||י܍kmL3Vߑ$0ـq>E0}wԝ!=L,Wt qƁ<->ʐѡKk0w;.rpe:w?#8'Vhk zۙRpƠQhO#$Բ{}yW59<вL}[u++VIE042ihķ-omܨc"#zW[xFAt+ZzN 2kwtIz,Q:#C3O C:J#:mN/3`J@8&[5}$֐Pʭ=r 1tǧnձ.*)Ϛ}!xÙs8mCA1W낭EyfrEff;,!†ή*ngON]K);ww*|l݌ŷ%8v *UCA@MwGܑ [PN ?6N7/. ^!mXY& κAw`"{]āV4v ٣P؋'/N2>w]= NS:)F <31KXjWk#~^PFI0f皒9V,2/<@O|f{J2U˘]f?}Rŧr4k `8nrIR*Y%'dv`%dF?br=tjIt@3/,ݘqH.ˇ͗, ʖۮ3j4xY:tݤ`iY_ ;ǴT.(djBRjqŗt) 4U5㑿0=z]b#ߙ7 wÃdH%Hp4뭉A:Q+q `^rC~FtmGA&s؎;6?B-֋8͗Ȳ$^Jcc13\`_/P֛n~>&קR[_/|2R崘T!B1aBF~M(vj.aIegU$AP\&݂w\d 4ǽWJխ'-D&E_ЍpۏCj˳wQcWo,CkGw)e)csݮ,@ߠZ "Ju'6~U T ӂ1x[nf3*7 %)q eb{๘WrSA< <`Z.>CJ&rf*KZa۸pe*>Iu "۝}F 2A|R8KşDO/9 oDQD/rl%6e}^6ZL!p=9[eSs[by_ Up.[*C`p`5z;[0 vU!wЬ?[YqQw3؛W]\(,M2f2l/AqMÓNV3;, == —!zhOQAp/ovk־`<ě>r5 t̳MX_?6 hJp2{z| ['nRPIglI4[%<ع)+&`xI~i!CB*+yF?8'gKpĹ.[Rk"Z;)D-$Ք+)sHѺ߼ē$DEFk w5;q+"C,$4(u1!h9PzR 椗\v3;8Wbꎒ4i3SL}QνB0XkSZ/4$9 ]=[fZQBn ?E u636u hǎ@kYpX8?eW.?Qlz*<˯lVTސ:d=1.o*&}W[0k(JcoM\r;^1m-$J]i\1<ʐɼ+U:RK)ݭj)Kn! y[+]v"yTOY B!+u˷\'[qWtgH2S|z= =zB&%.F>~5VkT,"B-~@Dl-m OR$_JGՄ/rNME?~;M2Ou znӲH%q5cocĘW9е#s>B,wXe L:Cx(!a *"wSQ=t$mD.kP\ݣ)A7q 52($` d!:JN8F,8oנkϮxPږZ.U8ĈDpY|g\Qヷ>=ṗb*7:FhWodwƛdNPy& O nmVٹ.UbŴe.DNL=\r YRW(Hu{lU;3jR`]0&j24JDc4KL["\H\k5?eA _^\> ug ެ$FR}CvOM4^[Q |KUƎR0s%-Bӵ'S klTzԿ3V 1,%nP-D! ndyq*[؆[GXli|M'e q PQfx+NȨ&c UFZ= Ԍ9♷er5 7$i.pcҮ 7?_? BYZQJ\r]T#) |xz䇪"%ZUxzX[F",Ga xWT2YYV,dh%)pg_ l%J?skz >QG5b t a&8}/#j8gg)󎑪ޝsTZ`.B֖2`.9@nO7#Bq|҅Uq^ɿ ء5ݾ-//{Yo!EMRQy%)oL#ٮyuԭ,%!> 1*F _=N`BhҺSov@<=o0 e;mSB$/-5] 4Iq3dC\<٢]౫9S(:j>dmf~ـ_l2k . hK^Rl띨qz=(m⭖ h{8}jL /0Ṉ9:~+3z ^S/ UZg6E=EAqw CDz@*kʩˍc?<;އe-vsR:nhކ!'4ADH#2ț+;J,Tϔ lB͟Q:oڿ֍ΦR<1m{ha Z~G뵠O缄p >|.BK|=ؖ}g &䷈A^+jC HGψftcxWM^Ip4T L f9ƢNLE dGh nP(ܑLja+'[իχdH=~:x\ZK2qw'"?t<1dKjK~.x0)VwO`Sҝgwt@{q@8-Eޙtʷ/Q\,Kx*~Zً^y.I^a~R ]e<آZW(niPJֱ~DY ץ9<3&GAu}fl\"fc;rX[.P iFlJ WvtJțq@mRqa#Ɗ܏MyP?t~ȈK>ج&eB?CHvw$_k.x~{>ҾÆ>ҟ7 n6lF,Sn~WpYF.+*T~!WZRqrHlG~Y(ka%W To= bϑޚ4k"ƭ"6O&3uJ|9stШєR(5>:6qN[g h%͹pc{PQN!K\h't@uXP\S,Q61$TDfcv0+0U|m4@|q'ḇ  P̃)q+XsvKbI\vR(O7!&H4}1vA+i{n5_fzP\3HHL_uР%6|CxZCipP*7cNa4N0-va߹kPVL$?CH]9y/8΍,)EEdV=Ho 5˖d@=bԦ$-jt ?cΤ3pD .5"2T n'EDFپ5m.T03SC4iQ%|M^2uh 줈jsׅtuqu(ĠRF0#&}!}ΉElYG.j$b˰< Nb_%s <&5&zSQ9Èh^ [7Cv4 -*]H^06Ofh}G>ԸuˠILu?U:8ZDKMI HGU 4`Mt`JbUs| ȼ89r:y &HC.fnSLۭ*Ug_o?!&%BԈ;b ۲n?pX&Ix+p .K jOjWKػ9x9|rH{G95ߔ.IO8N7X4ӧ> aD j1Zϙ$^smء߲]Rh/q6bF}!߷u%F4,[mC}j*?XKB<۾Je䔇sv O0n3RZkEb\, m녗\1Y!kMg+^wgrAQHP\d_Peobyƴ{l bRom J7E|djk'ܑzκrNMQA*s]Sļwo9 EYK(qH.~ICV,3Ayn@voC7^V^+ӣާkm>3Qh?{]]q%glzM{tJ]):3֑rz ,e~X{kje=]Dk$`="h#_y`#u>6h?i % /q-0G .:].(NJ튎k|gߞm~eˮK\i^=!Ҡt*ɖ]*eO\9QvC&r?Q|=rH^tCE9<١h4)BYHZ@a'Pb1?,V;X <:`+ĉMS;-0@bB3œHV{c}[j|$8+\A ݯ~=*Zayb C=&ՠW 6ce[t]0qiDẒwB; =2-Аr:?D?>r I޵C s#N\p̙TA_P{iGUn$Z[G:iD &PE]w)aehBVR1 0{c[PW^EMcNt) :32~E HtṺk@ꮂ= +%t~֛GakQԗ;d}YL'N)<ˁU4,δ%93Y ބW$3yTy9)Y"vK?~x /> StJ>?G,0</.(z!JHʷA`lw0)&w~ 4T4.@FQ( :P2fEY2[PY#̽eXC{{Gwz9<$ݞ#+K6XCӤv֘!{l?Y|˦s*'*=*+ X9vo'/L84ZqXV IOo%3*Ue< RD"B(vQ 2{⌲-x ?Jdq24#W#A$Ӄ=!^ͩW=8w:#v{\K|A` #/=j* Ž9 ZG[WYpO쁭i. cU?\2Q]Oxhf(nsfse@d,0Gu51gJFn%mX4!lyMrSg>jӡ/ [IEE2j2t&>GX*hw~n;^i|H̀S/."n9F  WbgWzPxpRk+X8~{ gw} .󇨇*N* o S L1 ~m^ hohBgA UBpo>zυ!k= D5[kT#payXueg6:O)0GU&璬KF4M 7kql2c[rL LP|̉Lb)^:9$/KҭWFЕa $g fgE$ytwW'{̆jBT½73邡c+y{]^_leZ8mش3A筒R cf8H_ <ЭѯEIUmǝC-]xZr 3FB^mJ{Ald|l/>w ([ߞ^EZP.o<8ڱyXxX4 㳌[Jypӑ(G{Nc*ϥ Em xK'?;T )_9d_2c%(2պ9CZMf{iJ<U>h4ʁ&ddG)@22Ud;3\2n<4օ格ϫbUjuz&k%-drQf)L9 Lӝ&q#s:g: ?_!ҾȰ! 09p}:kP\q5K$+rXD`%־B<k$a/|X4OI47}VF@߆tJ2S=[/$?0 DHaV<<`4hj\Rf=hg0Y)?|/_@zV8e0Ԩ MB?$Q灂d5dzEo1ҚQ=/7/+w:u ʫů D:gh͏/ V I(}2sxwbHeOo#@.JCT٭La>DM&hBgV~_ b7 Pt͜]HF|jV&r~{܏i"eͶ>2sm ~L'4 HJvp/nسgSv>'cR!cRWzDwvd Ф5*ʏ* T|%Q =m5z䋾g|U9)/}*ۗ2pьތaqwW.hޒRhh^lCN :Z&ДޗfDѳivbN~JV8EFz/Bn,4j~sGthS>kZ;~$3~e:QvT\HDd 3\g* lהAEnu>/B{Vwkdz% 痿*l7㜋m{#AԛΟI֊ƫŤP2aA5ا.L(dtG^Y/(}-4?-!N~+1GJ2Kk)Fp מ \ K:o<6-#sMyHV-%̩<~c]f(OeaM!f#%?Lȁ@#_E6׼4vH}2Q/SBJn(&3yi_A/ 5=sQ-`bqXu lTPv8n?UV"lj0puePHMCEB$}+gc2~{P-cKoHT&t,fԘh\w3L*?'HGrk4T59bFn\D\uG*">JNU'zAحoC__k7Ja푿I/U^(, x!2h [TaEAeFHmd iYwYr:-wd[+ |6DPH j u;au1y9$ng̬,|Xdrb +3KM[;RrDžY9a:{7D"c~l6|y9-x!4d$b._^< "u&Syív𽥮c6Kk$<9n?{lܠ`UUޭ3ZZ"fV]*G(w͆VV4 L;[1*d4n I2VS2[کDQl` IBu4;F^ԆLY%W[Jpvj(99G3w62q٤R1-?9R)R)&ΰ!@gƛ S΄qD$μ_mS|2,ۧ:"BX#c)29*]N6ɳ~'IQzsXAB^ 5I'r_[>ԃ9@> ׽oPgfQvQpAmcWX(oF%mgTbhf DPS\YUG}}<8xm[H^a pwa)X} )k,8I{͊EO㹮\XsOd#P"KV)«D?(GLd`к8֣CBQ|Ay!hǨݧR} j/0~͓ƆĢpoJ[^:. F%ǡ-7G}f '$xKDnG$w]kXlEB gs8&cEKҭ wA]CITh602ÝNci>–]ymrk8 hZZ>0bI/ڰ#t,sᡨ:4@p-4|'y *qn_Ba@f Ujځa<<^IeN} "Vީ*{i~cPYa"LZp[(6>?N%(nzwVo ow:ۇEy\ cKޅa~`9_ﯷuMTrqJtRdqˋ9sӏsWi\mx"q;?OyFn߮ i->v?6:! kהXk2ȃ>:&{!{/G>ߗL3}@2SeR䳼F5B؃Gnd^?'Bsm'.:`J i _H0 uWh,;e+_I3i)g ?aԭ8Tb}vʑuKIt!Wɸy˄fiYw-R\.s󔙦LC?,}RmM ΦTNsQ%Qt"P /bbg)lF-7U3u.W+&{ @+*Rb_j=Z$iEHgJ3,=PQ%趈j!>Nb-yn`j&YX(5u"R~x^ b͌ZYX0_g:9 4%qdZbjXfe 9TaW`(2i1#r: YU -f_|Eg?}Lye_ b8N꜕!n .8eqؙ|PD59=k hw8'&M$o»"5ᘩS2G`lE)?Tu%{j7ƞgb֏),=w(z2bzn`q>?iFSeګIZG+◳N&6nn1 6潤uS-Xn<}FZ=W-ςJ)?U*; GaG?- Fxhc-܀'++.tk!r!RĶVR9&ajYKX6r5҈ݘ) G)C6)Ks{]YEai)E1``g"k{۫AVn,4J6%׽pK@"\y{̘Jnap+I// p,0Q%j>.Wp_ۦt3Dcb/&]YE]u^5amO~* esR45$b) 2'oR b.,stGC/+ q8k_i|p0P^guHqؼف(3r&|*gs¥m Ah$80[8fN\X^֩LZ.ûwo[bIڏ2"ӓ/f\BwG։@3GP PRdx }0#fR\ ݽ(ƙN M4ܼ,l8AӥM#(zφ!\+y)UVT({'IUӐVuJߵ(Iv=)Wt+z=HK?9YwO*@UR|=a˖{WW*_$Nה\ T)bxm};$,4b *TjTU,~B}o]ɣP|c-$aPDݢ]ox+Ճ gf7Flouȗ=;t6vM#?|ww>;-1rOQv%ࢴW8w_Y_c" &YPiywKX'DBm=BDWt#DmϚS#L  2&.#Z3!xFW mh}k}iax-t-_ ;qj(Co6Gm#ZɎnw3?SW|Na?8R(^YfjvU0eCUߌBylB &qW/x|eJV<h)(䰜#2F̲~ ԣ < *yR9J3/ -|r![4 [samNB șz T: T)`i=}Vy} R]to*xn>E>;Z\3UĦ"UWHnQa!T ɠoBH@G;mE:.։I=ͧC,MӉRѵػ6@o:Hy ,`8teJՀ~@g^[BKi|G;(׵}(0 Fya&TI6ʣ]6o4smLC`w4,]QNx?wwe?AT\(hs3lt3N*C )"ؚuK-a&i>qT-Z+`r˃ZlsV?mUܖDobg (`wo}i<QdU%\$6}//+Bμ2gR6|RY}K|s0P-/K&W@wVݡCTcvB/T'0= ziXv (Vܭ6ED gr:9-b`a~Li20ϊ")J\b{/BATEl} u4@a'(i D`ChH~\ g pZIT=n4m8P/qnP_䙍+ ϿS4"8ov` /t &$~on>~;YG!E۲4*wInOHlw\e7"+˼vWQYݟ7f(*fnbq<_*40΂3-+kAcă{xmAյ\;0Y(6jwug |[G܌~(WZ6[W)>/Q̖ڼ+AiJD;q>A/'fmb㒁QM }u@9 (Q'^<(K Hi#Jn]Py["Q^D[hW}LlS-[J /k;.0xԗ3q YKuyIEN)@`%k3sEwE'W!ܽ 2M,H4Z^  #Dc;7G!fZ:Ar3$qʅ=4h_壟wQe؃z%y <"6aPV 9#̪]@ "/T# XfsD`)J^o=Kz˩?Z-mЉ(KEׂ=LeFV n ҃o )ʚopI)_ )|+q`XNNLHh2N`Jؖm;9qO2/\i~,^8x~J@Ջ>Hˉh0Beݴ75d*l]#FJeޕapUyO$a\6TF SSccsM.,T۽۪dL m0s (OS gO5~ڢz'-P5Q7$]Fs5V_x*s'RNk3\ytt[9Q[\BާY|2d^ϑ¸UaU pd2qJ5sKw7 dZsg&&4Aax(6*Y2R$O%(n}!y Q(v@+cR2vX0r( @b6»v3QOQwN ;J 0Mm-'鞗jX} ڨQ><ԥ.CRh:zmcS@|#_yUYxNqŕa.pX{J֬wCTݟK&^rzDM|̪C;lys} [@9= ,Ii9<N`zG9zCR蛨&c_# )?7_LHْ2ǰm2ĕr^PhA&smL(+H9r`".Y層}^b1]MbP8 Ja)W`w%"(;~ q%+(05i_/3d|J GZ[7W4dy7 1Bd;`JCsk9qۤ0YV$JڥLy*S=.l9'/C4m;GXsWKDQNIM@E| >D;Rwt:i[\,vi!:wBRRaI^?*~1r>]CߎA`3@o AGO"S tWYkVADHj̏C(V2.4n.WywCkGvkq{7+<tǫ~ٶZdL p4Y]L6&3_q<ʜsb!eU9;cYE%먿+izm$>n&ov"ti}4gSL < b#,ATu:L`7O:9ߢk̪v8˛CY7TsΈl$N8ݏ$2P^0w= *ãAd'iίcm6TA#y'(=9P^dU=j+9R~rqHsۍ;;u-]N_o#!u`0 1(x$DʸC2rhG ѿ-TAېbkHfi39j"۝goY} ]O|1jgxMvt4S/۷t~S8LFvnbB4qAnXcF`TЁdC/TX!̷JfXx_M YcNvF<7 ^ٰjiѷ{[Nx_>Ncu? >dsnr`j:xgA9-r'|BMGrS2O }7"\6QNatc)*/81r^62 N4 ym :ْq!82*m*,S9s3 :v3RP;HTsJ:SBMJ#g#A!^X,^zgMaOrx bz^7edkP /WdHR_Xw\+R? Ŏ#ZKnKu(rPk|f <%bn qHo=$_w۝scotbF/ 2 ߛl嵮INʩ8jL+./9+-bpPpٷ&p8 Yَ4 02|Ndfʡ$7B'8FRө3|VXPY,K6pd4F0\ƹg=q{f, yY͚/|}8C3f:ˇ_hz#.b\a7% 5y~ݛ|#o Ij4 T,&R\oBa n1ł̞p7$#-joe{Q>V.oSǖd[id>|*j78uv]M.h+ɷ]9|٘"q&6r^Y=ug \nb%jUbP:آfbl&ڻ.+2i*(t`箟eMəH~ɼ IdqZ9 B:'Ɍ]šGlDw`jqeΦ(B "GdśL[ڎpB+(/ꦌd\];־(e;5AS-k$sqT9uzHlܪ.P$݈Azɔ:(o8\RZfVw ֣h0lnEqQX仮wzh5t?ؤVAdRVOTwT4h,A9*Sh܇#zLeJf EF; .nHB+ip7i.F@((9\|$žهvi( x4pPs"ģ<秋Ɋ\C9M>,! dRp`$d]\f$H5f1Nw62 C)i Y7$ȧi,~w)*=#+ќ]߀o?nd:K&`c:s6dAt)ى˅ 1/-$`N(^n+2[$R 9vVzv}dS:sQKd%%~JhI]7 I+2DMڥxs[ݵI8bjķp}yDVc%%թ9FKR=n9ZG'ˌw\54iQ{37WQ U+a#pK&k  _;ɶ5 2uJH棕+ 6Tr>Aʭ A3>礶U?@D+#SXZ T(WO[g7밗4cD=L)fFP3EIz߹{o 55RCv+!.P1f(m,`?gحxTiXROŀ(5*V.۝q㯅$wxճW ^B&?g@e} b(\,/t*+5S нQC1 an-Ctb1%=Jj r螁7,Gd Ag.BmX)RASq9x9iVa}Ӄ%(lN5٦(HĆ'yKT?I2MYQB. kx+}̰1_3? R9RAOVDQٵȕg8>cۓRdZIR>"^v~.լ&+V;V@q[tN 8Ld*2r(#O'amB:NnQE'G%lڃv'?q^ۄ !n_@k KjOk3qmtc LѺ+]o 0d^QfR3{`?eԍ7{ĥ0_=Dҗ;w:u[oOrݶ뤒χGcM$|"{ҡq?IպZRJjYR]j,Mu[}gjuQ]%jI|cߤRjb$ T5YTp+Q'G%:xnۨŚ:!\h]Y%)w"OL}@~j؉JJq\\E-JۼDt*fCY-^ɔ$OD`&)ifR S_Q7*Ugh+>id:!Uv(?W8ei0 ֪At k>޾^Eo=HS0]Wn."bN4Ӗ P7}/,FtiW# $D$EɳCjE=hV=Q"[]o0yu5ˌxCAY5ܑ,0ճKӁ1x7V$F@ _!$9C y*ִ\GN^8Kͺ_,OJxq7|U~,\\JT) C1,_WȼJbs#=V ~`) +l%ig1Y~%q]cLvXC%vIq d c||0wrjPM ܂ lp1(Qbb 9U1G 5ΡMfCB4ܙkxQ0LA{|?4N!c{7ҤV.TF(YC]#5rn;5#Ȃ p@V.QNRC4x\gӅʁS`8"hZā٘H\{$dyTkD:{~?b1pyi|\"[g#$":luT[gxBirLWԋ)lϻ7d56ÓXc~J~5 0=~F%*U ?9M"Ph1aη8vS΂d^*x,nSַcf*4lH<8B\wQkSЕO/cl&ROC }|DWiŽ$V\|`p ~R65h\jw]}4[Az2nzHlq8H7V h'* Dg3dz>n\>~W_ ~ȿ1ߜf88eij! AriO?_mP8顑<4;^@`Z{x3~բt q*zڰuG4;_ZZoK,P!>U|G^"],> QI9,)]\Pcv$ .L1԰F9aݞdIv7> xV`h}-B `1 3,"߸2P}XWbiK|yY"ଗ?&z2oQ[V4189Y1sPUmƅLK]|4ƥlpG}$UUP0C~Gk3QE<O;8oH> >i$] ?q 3%mT]+(w|Q{7RCiZ1  kTFʛi]5͕> h̵!(#l+cSTĆ|q*3.'%h oLI"bZ3Rf7Єqv(50S==G"w3y$-\DdKfAO*se.axBsK´//X F{ 1ep4 4먪|NRUHue+)jRYk1uUNU @%ĿoIBB2fH@N]Z8FGiOf ǁ0cS^Ed$I [|[ʆ\w eQm na%Ȁrwܕ)Diq_32k~M+RjEb3LY l^"qS(~ 8xb ,s0ArU)A$n)XئpIZfe Q3_grpwG[菜/?jTk[SfA u7b‘iy@8yK7. e"9V$r~=eI$@ Q\$h^RGȴ2VtV 'c1HlԽȘIydZ 9lɽ:п7":g߬])9R` GV%7J R˥֭bF@C{ ye gISYD<xbULcAXiFrfc%[܎ X+)1٭Qtm+M},e6s:R_}; G暑C#M`y7;# Le.w~ʷ^T 4UϷo dj]P6""VsAnB%rH5H%T!TM3f O^-DGE+:>-xF_uJ\G|gFK291cC3jtjb}]2(*\z>4H,jsOpz:| p(*h%#6"⢩p*:%=1z9{:lg] B2C ְ,Uim6HBU_d{I,OĆ[pY ¬ @c 3A#9f0VL.ͩ|QT%mNI<( Z+D. [Q2}ZN{E@]79vq|yRs*y/9HJeac , WBpߋ; C45ÁD!Zٹ2i:jҶϮ&H LߍZVHs/35b'(0Ÿt7"c>ZI-uR\ѠVA?cev8קcձd[=acT]Vw>;&qznu :}r+a<1x6|]?DVJw,h &OŘE]gye"6suOѼ D͘!$ѸOI}=#e6 Mj#s],Gjm;"P[魒}+CRm!yXC­B?dlqe8TW,cbyMO/T;h4*\vf6 9G^.}[mhxe yCdWݱzM^L[$A "s'UؑA>T۟UuP&Hli$jkDh+ k"2ěKfݠ0ћ?$]T><y`<|Qk%jgNԘ@ἡB~l#>T-~H"׫.p3`:̦Bطkfe zD"? >;ks *х atbNmYq'c 8+У/В*Q=@ÈhҵZgc;@*n@Ռ~ R:] K?csDGD e´G]}yI<5FLdr9 d׳ny+$-zd RQuW>wބQm [͟oZ2Ѓxnw即µݪζ!@hpWȑx98O:u>W" BnԡR4z k NYա{,m$<'_el1\a+"Lp 1pH8,P`X2FJ>в5+N4,~X}$[\3ύXYڪ4ՌZ#5&uoˑB[X*U+R :bg\Ag*w/ ^O@f,]aNȢwj9`4\͖ ]9 PXxQC":^~b\?mU$ӏAԺXF%W]:?kwCGu4;*pAKh i>x|m'W?a7efu* >y TO,Rޝ!Ax ){e%ʿ$QKA(32?mMKd쵺Ҍ;L +x/pD,(w:%vB>^MJq bʒssN6"L\N0NehoQ ݿV;7=BGuL ]D g5RaV3 }d8^c&LhMioyG{db.S!9]DchTA ALM{SS] #tE誦FS{%\p@4w4n׫y8=rjdc!6d]|K4lkJ]k~h[@ _b 1@UrY{6B V$Fw188GHlo"!;MȄa)$&܏0A3"D櫣Xr߷r|H|K|#lW=$R"/ЫaԹ @N%sv!Icf Jߏu}w?2u$8AQ~UcgjO{ ''á[nWL4n@ Mk7D56ﱆNdME(c t&*?IgW,Ӝwә괙Ƹ68uf ɓ6iM 379;7Y}q稩K馦։o.1^0$G_ggb)kBu83 qx@08αX7D LنW'1bRhV92B.|n<&Z[f: )3=Z~sXH3sn2Ta*V l(ڋXY֚MvDc~|x\=Oe}t [3? }E;S;pH~:kR ?%6`T/xV%NZ~MeznI)h=y"G)9 [[Twi-l7 Li5KfѲ+gN_}2l|ifP3{j>G#0I]#C }Hk~:Z'J<]K\&*늠9^S9e8ordU[>bx~{&7:t5,RWk7ךun7K ;/ P?U.+L32w)DH0ZeuD[lJ$\٦Pm4Ïk-{.FGo@:{4DzEQ݌Nl |`.媷LhceaL~14=L1&t$Rޱ}fJI_b֧-[p(zC\9ejFN+m wca>!$0ijlB;{N Mby)>s4'FPnOJPM\. 7h2Հ~e js=F `Mtԭ R_{ M]S1=36sƧQ̬&fZ ܷ:x<]-g ڂ>,KMpL443Gʘ4!h*4X@ق};3FmWSc!F!0g3*.0Rz7˳Hz(폫%ʳybHq+ i msuM~+{B" ,1XE&}Eߘfv.&X=q.l?{UC!4$E,ɊS0$n1,=j.~Vr}ս]Au`f-⛸ +"z=8 x)դ/ B#E0#@}lA}7F8]|ipY]toZ`9T^'9`os@tP|V_~%!*/ \}lvN;2rmetjGd%E^7CmRC$*xd/l=#YIܩS?K/> @!9泹(źk?B&Nn8-?UO5Z2MS}tc`P \ԟM5ސ[ְ,htuT4y33F^Gp ˑ{]zU 8ޱc2<6' 5#%u{h#c[3tT>`Si#S񴠬Bwl6(fTM !*lpo \: JϬZ?d% W D2 FV8ħ`!F*yScG> _"NaL$XZ(NI+jw},7w\-@|=+l1KIx hnj'lcձA!0s=7>φ[m;[ 0^H~W:1~agwCn-kIw#uJRă8!>!'(qYl5o[`P}nk:0 ?) zVI U * Fnq‹α|9` pրN-~A-=kKb|'PD7|-Tc*&Q+nsQ|u +YTbR#p LSF, +' /ӞvSӴW K-Z,W# [Ta\v:'SA_ܖVeMs(hs4)gЎT 01>HO_ `QIXg^ pmψ<% D;Bfhe&1멹,MŪ*C2;!}q$Krj);<5K`]"a֫FЂp 8,:yh]6K "-ǧ;"Ogut%E|P`^W\ <>L;x5T8[Ɠg2$J.ډSeFS(| PqC}}Q c}fn\fIy =^@j{Oc%t`겠,'"#d荲_mKo=qP0+ҁOZ3l5lfy:cKLwG 兽2"L Kߎ]7$'K*Tջ Wm`*2)[=H;^|=tV;61_rCtj_d?@6cz]0[Pe_8c+@ġ7waaze\[,Z _8d#9ߺ٫dh)9m{ x~d@.0_gtK1)*LH ڼT&^Z!eHʡń( »ݾ]xB-OpWV23:Q3> U{,uV4LzX?_*l-nj5ͭ1?݆H]8s&l NVKc.K;/|gBׇ!Z bC< sZ6'AO<"U ;Ib5%RFM Eh9d.;:UCy9S$ ytI}gC2 FaV E fW#Pt5L)vUBjG*`_ SnW,UzDI`@^NQw ){-ᙡ8#s{h,`v!&RiU M7+*?d`9.L޴AʼnU,t" ]˻8xV 8^1~B$0NeIဥEy=ܣ=#ixprʿm_ IVm|xpVTZȭ} 7KI1ױ(Qc xp9Tԍ8F54f <%& V)V 2KLǣ!s&\l-,MЙ4إB[+01v.<@%ҁb["`J8MC=2o7I77z)ab 2[,=ņ.lqtm܍)S,cZqhvhַCvBg0|}=-MHAswo˘(nHZN\y3$w+v ki}M"8v4%MyPMik s1BY0T" 9J {C]?|0vO;*pIѮX^hT gУ.wC[@3YN7@ep- W=ۭM]Z~JP1BȨV`o)44fz(Z<5@}3maA[ۙ9'^J TCWe6b(%^(k5.5Ѵx1j|} T[{{Q5@YCJ,JfМ.1juc(rb?F3 GBP?O ^T3APu׻/25JJDUP!X*$;ssv o++Whly{D5JP/cu ɋ۳.:^nҙ>z0㠢i_qX?}J3#"s,"OΩ߆t 󒓯Y! % -ɰĚ&<:`-RKSJ,2ER*{׉ȴOQIdo?ާnG2zhD UWPC0|x)d Š4X#bTYVc Rc:"A u\q`=5 j,O[f 9ۻhDՌ (B$[>*Q|x%~z\yT.|b / f e|jǹwK1 1*#%6vVlO\&籬7/iht@A`7MB+?z1i")} ǑK## kӒt8>_kxKh= 0nѦnG=V|%zL43nFS612~:W-xvG ưhFDcJs[Kǖ[RXFhˢP2%ʹ߹G_fʨ-4 [4ԃ-ߕL)lIF3_&,d&STƽ/I)8{D䄷K GzPլ~h =7 ]1R w15O ^<_(*c䭽9>3QQ ,o %Acq-lYC2~8p"2nCFn{uIzQRw*dZY!L.`p'hm`dV8 hG6 XKg~x;?a|wM8:)?(  @̊B#EʎڧcA٥ɕTf"ƒTlV)_,lZ\$1 $P6Cr ǦI/o]hƏq]_wd%:@ C_-uΊNbmqydT+ {=|؟oY5=.,5XCY'QHG*q\\EbC=1catnNk s6'I e+IVj"O#Dn0|jArr"Wn|~y J,6(!AS ;T,ۋ{A`^*f\D_ζ%,-? O͐=8f4au ΐAn>ۀ2GKHzXmLjl΀"48<ԛ\yTIà.^G>TOCCnSeRy|ዋ[;#s*i۟ Hsh8k q&Ӝ]sGXI|/ȹy!iA$[7Op89"_+苋~#8; Gǩ5pUgcw|:K:Em_U=CuUElJk7꼳…A;WꖽӯKG$u M}NT>6f#PhBmva%o.5/1&]ͩi x,x,%3xj N5Cdl{7rCG b@|'i)UZ4"QC0=jXmUzuH;7E/ ꤴ< u-eUijɕ$yJdw3q)ȣ&v߮j #wp,AJ )@ΐMr~YBFH;6, QzemQUibP%7UvvǸIǺc)EFYVA2p}4?XAr닎;`ݶO #*;_98'IO.6O(X R}\B+gvֳ?9AQnDx;W aa`À%(޷$쬦dC4!lԅrn34a Jr u[c hGax=3\GO=0ObPXizsLX涙K4w+̰PqY<]3VR~Jڊ<)h@=PPy*Y3! QgG.~*/ÚfĮ.=腷R^}VAi{HnҨ墥ɴJN/?~hWwXV k E]b:` 'Z p z7lAܼ_?-s]$N Yxt45;3ZqS&2[2*f#mtВw|oOUA.ӡu~3г ƞ; .kf?q@j]v^= 枔TQܟH=ڵ=޴#&H TeC}% YJ~`B˓jD:)b/uwxS72@h5@ske 2OD|εi ?yCJFf?HgH&Ccm< o~W̡~O,q|XE})EHfd;v!BkI>A>cE3yEj8Vx(?"lP~OD..^ߍ9;hAVX߂/9V\9n?4QTsD:1*d_w`O uk]yu0IaV-vPX!%gU׸Q)6$`] N~2r3E` oBDY^di Sʋat@B32a1Y)\l*yvXn .;}LDz{^A,תlOLFxE% 6nX ÖЎK^+\ |&O῞VF\6= TJ-wuUͶAC[-f4x+zRQ \0a'쎒̄K6F~Q=۰#H.ሐ# v_}c6[aRڐ {mM  Qmc7}VPk6CQnd7Oz1\m8N7pr)@/LaS++$PË:@.HG#a`Nm n%[6Ζsf}&Bt46xځԠ! 5o1L]H"A(C9GG+O C'm %,RLSɤ ^otQ#]SBJ0Nt8{^|i6Pۯ{ .\2,gZr$y,vVrOF(!u Z*= 51 qԑG2>ゆ`721Һ 왢Jn/S4,ਹ(xyHGU?ᚭִ:Lcl>l63`'46גƈr,{g=J$i9ҹ}h ^d'b;KU=H "񏤢g(4P3 bMٱ4|oiE6ٺmɽmxգe9;cM#Ot]SۙZZm;(s$8}s9^nx֢O. #Ǔ}_ӲGӉDjT]vF)ˡO Bޅ+_r5X{^V!|mKXJ.uo2Qte>ڣTEkpu#PJe?obUZ9fnpi_ǸL9ayjhu ǔ JH+el qzTA|S~wH^e\QǧU͙shKXQ˾kO x)[8_N Q"b.HO1 hcs`GہbS̍|w~ӫ$)Dye@ȳf M~pi4 *u^=Qஹ4hAzo/iiQLl7 s[g\`bI꾬FD-?ڥrhC+C˒N}'#B2z_uc=b D'QɒdDv$(.5,!ℹtd0 ʱqX̭6#O ?mA~+*=Z!|Yt^* EO~;SK;=MM?A-*)[w6(9`D2Oމd ,܋y=}'F0cI@(G7 DrAPE@+A=GH"uyY.oΖ ~ja 8"Y@wC M%LUV!?Ws?';.Wˣ/.,AF wATׁ ~[6p7m|xa#`"QX!&Δ굦'}jb&]q^H2BNm?f#7B6S@{ Ȁ &\ϑHʘT\ Sø t{i~]sқZzh0 Pehӓ ,I ICD0po'w:;ʽ EFjv~l;G7}qUkeKw^'Ne:?D.sb.^\NQ Fj ~ʈA})S 3հt< (fz#PH*#\<.Yln ϊ!aU[ qҫy?)s P,X{{w9c"Ϭ5#hqxMÚ| <7iGxyC4Q5w8>mapǻXeP{C|*Nd !>Z=c8? <a mV-7PzXMWYL0yaklyW\̴Om t{tm~Si/L@,IщLݲ><[3RwFPqUYΤVέR6mxYD.?\c%?n7 /TRP!k'P5|(i -DDo}1Y5aا_+kQ`6 (uY؎:+AC <9333 IZbFRaw1*pOdvZ.`D4èu& Mj[vgx@?b_(⃮y 2WfWu%,</<t&'[~*KFa7a|~N>dl] Ҁw'Ѳ+}Fڔ*3wsӥD oM}Adec_YIa{$p$Q|CTt#3$*BnP?>ᵍ!B9̹X,il+h:8ej P];bB .at0LUUmN~G?rQ 9^μ;:GH$7k ʅ XtIzlZ0_mm$]@T-9Xbr~j7Q;?fF嚣Xܹveꌸa)5!y>fDl'<#7VEݱ'Zٺp&/I_<tQt&RxEB?=,O*"gӀ8|}DZivVfMAt8cFPVANmydzc1A\~b)tқ_ v+\ceQ?'Yv\jHe-922jW%H̾|7x/H ^Ȫ*,U9l_F}'XK$%M+%&Mjbr {pz|I|oDyk*XDǡahLǔ?onZq&sR׵62%GCCfod(fAQąBG2mf0zGa>T50o,sG܅=aT0^l"xyUo7OW+f7}"ň bܩ,"K+"lWkb;(e>)cwfyUө1JӜpUM=3 (ydwE'FB]9M }mW؇%D%OO3D<$3F O᧸tn+y9D\q6G>̈́ ́qcbz2##<ˁWۭz0ȅ=zpw̼?[HSu ~2Tόzw[gBAY#A}뛴(Nl]qgjfނoNKP9졮g)|,>ww`pqF ԥimUBw`l"`FfTLk!9IkT\^ֱkgpHvvqZ9n'-*!WkCGu7Yz+$& ."P9iޝ19 !k{nyzT3;/BhKt246d~ 03lE7A;ubS?;zјiãW7^Fnŭ#88?j78]&ujT.7d(,k3@;8nb~[QQ]&-2ؔg6(D \mf5h/3H=Mz5~0RnwΟ҃= ,2f? e@-Tvf/~*OOM=U{,&@|>c0[1#f˪QB ,uҲy@"w=[GPۤZMS"F$v{\ A>X'g}GΘ"WT@ZI_Q2SKrBS8YMi4cƯ;nn@x5ط R]Vg^L sgsn)N^KKid&}^UD_;O6Z򔸫s j'm3"ۮ̽6>Cގ|gKY@X'+{h9Y'/xjKȦ^A\Pz ps?ZKK:ڢ4s[P Wk3p^l^;@hqnLy-yj*[$w(oXz'vqlzaQh'c_ley|G/sMi#/j uNP2ܰ1C\^bfa~bu F*k{A]?ޚm7bjHCýZ2P/jWw-*ȉx¿sTHcoP̺YG0HJW2yĈd +vn^m'[".\l4cn.oVٻyC!ԏSd5ĕoL+T+t0`xD ʦs$w2EҋʖG2Qf^,I\} ]?k: Sgn~;*'G[jgAf94Fʁ6HƗQ"XfTNzTPw`%M`3щ\TC >I۷;o|K 'ĎVO.c\ݮ$"Nv.K!A86/^)lNeKdXNЫ{ ͔&\hGND2͘vџ&:!z) M$ٽ_1lAϋofs\kOr7uc ^^JHE S3E^/] [!kR"8-/kYgEE(?C5U ?0188+ 9~@OD YӚ hb]?r`5PL-Erm[":X:b Q&봣$ʨj'\p*7J8SéuqHp̘uqlx$D31 |zОBXܖ:]Ҽ /nҴb|;g ;N{m?j@uK].XsiM|>}U?xBc٫)ңԒꌞy]a; YKcՋP$2Z,ZBVo#5  E!K7rn\4l[UqL>830F1Y*lS'2?fV<o>ܫVAwpϭ+6z:ǘ;(׮M3yٻhitw*ݥžJ!y U2kC(Pax+›\A^"b8c1EN?sޔZSy Ic4EN҄Uֱ[Y<2+" "@YcZ6+W& ɫrgU.H޲*"w ȦVV0񍄨JP'q? >\!TU =ms;):Xjz  GY$l'j>IivoS0'n7.R6a8e(\+V҉ƒÀ=\N",|xW1ϰ+g5LFdbԚj|aI"a rhGw%}?;v3{UFuaF|V Yt! 7=VKQimV"@{'Qp/!L1/HjU&¬u7-<9x'o7A(Ү$#['~&Mtܘ61(= 'J %k$4NEt8,~0N`G^Ч_// nR|ѠMwc_ڤ\3Z :6C6HDUU&uQu5իtgv5mI4d`n_oZg>FY|]LNe ~Y9Ӥl+~PAj_on^=ݣ1W8-HG6PZȞ&KbYQQu»͉K~za7P |S['UTG- 5#80N쀆(I%8M62( ֵv/b@qQ6joyQOГaP6֤05p9pJ!dd^U [ȅ"$"+V=|p5ؾ Vy퍶B |GA>y-UkQ;AaJN[If Гg"8&"g~^wbJ8ljRJ0bDYF9`rcIu.յ!VCƘ2dʱVg ?t9&+NRO/h9gӂH=_L˒CfI>t5V胂 8 #( u %]YHyZSʂ |?7K›^鈪ۼq;WT\A (uՓPng+;Do" f1@2p)ZIx㢶sW5RҡUvq|0= % [56I 9%Q3=cqt/tg \L5\A1b$ u.oD;Ð\ k%޺PHK߮@dJQbQ.$\S|}loA3U ~A\߂¦s늓܅؈@%9`slBL,KIzadsPx0T@x]c M'gtzjf/~,֣8b >HB5hn!1HȼIN6h#>/?Aq0/2`_#|+iv;[Q+f]PmY@[T86J;3t0D$VŘgt'+2 BYe;kAaldoU B=.{LvKOZ鲫o]UȞEE)!~RRfXl|'q'KJ_@GGV5=s\ IfyjvF XЈvv5-QtB 3SOܫ% ڪ Kݽ3h$@֐2MhR%@2Kn+>[2x@+dl3 y Ng.f ڇ#10߆}ÜKoTbetzk*=MX>>u'㋹GQhJJ Xy@P/X./CbiqXWn=-DskUq{EQ_57͋ ծDY8תr2BƯGRHBDyNY~ܹV9A >7Er__EyѪVf(7=zX0L2$L^G ./pk-$#+a,,oaavk7 ְR\Q!H(( % #Fǫ H1p3 @G+ۖvS~&%=7`c)"mQUҌ Ahf_0|AK͆:}Cp/nP57+ZDN <̗7~lH i-̺u!XcGM^CQ i(WVJl?2"YQB2 HC2~#hҨG啉z'BPIt6'OuQ9׃*/6ަ8'7 UpwNa*J@`L>x/֖ɁTyR:L!XhG 5,ZI Y:>̈́(V6k>NWZ8۟_y{@fXhd1`oˢ;3tVw&tuc_2ץTch'2"G:!L.|:9.ؐ3-fmK͍Mz{X_p wVXT JߏtBZx1gE(X /I\>EٷӠ]Ѻ+P{v7ìZ=h/L b'2mVKSrЎWާD5dv0-kYҬ׎d_hD Elo/Bɿ;trj ѩAF6ҵ TCy(aOv"UUGo) lwPya:"rV8DjfQ`K"Ƶ+As<\ ({fe˗K`8gտnTx&xݘwЙy`/Y`~ ~Y+F\%24dmA+9 oC&ASD;?azZiL^,n~ п=D.*%?r0=pqˠЫ .ChiŔiZK֧%+zX9͵H'F5Ј>LeD /fu, ޶^zi%U(-QiG+(sX_ -yLi+1ggaܑYqߥN xҷ/nrøNa*H4U`8\?͝zEB@xSd,EЛ(U< E-GR \sj8o|î_8F:" K(bťY{V Uqe/1R.*,ANN06굱=ӥGtRS9 Cj;:>k 8k=WD ?S@ >Jg+rlFY |A?FF\+)B:aN>~"j3v]QOMz!/&.Dӡl[̇LE"F xK;{ :K + I_L;#ɵcZ+$V70>Tb9SbR y3w㞁%Tn1W 'o#%D\w :$C=pv~[ ś0vmZfTnsdW"X'ϕx% UrAy>&\m$N CM.hIqV*@rq<{Uӎ0ÌFX72 T:w~>Űf1yCj+a-3!F%V}Q5g&G]@{K|wر"1t)N lsLEj m*P_A<*YsQ]~Ͼ~o-툔Cq0SQV;}nQ ]O?& 9԰Ielb4 '&ބ%Cw-gU|Tb~ʱ#{rA&ld]F?su@7dt9A>0ͺ[8q\S*VC?̉="_+{m4m1_v3T7 Ż[6qS z9e9 uo븅'Kg&k:(@S薻-ެ:'8lߛLK')b޸YȺ*V d3g{gؘc̔-׼ι%\a563N\etFkE1?n^]R z9D_Ej(bNDэFAwZMh-ĝYXaS[4xG{;\=<5P^(=q5JYQN :_:$e1z`}!@(m&5|a5 PE {^x(4l\YESn8jVoqPNMa\!bJIJ؝}@{@Ѷ$ٝP(X!xtpATz HNHbh?Cy$o1i-ғ%On\XE4Qu=vu)f9 ݊[:E*(*@fXH#Wg{r|SFMLz ߗSLh kƗz9*3JDl -5`=Ya}8=!n6VǶG !itG|w{.VK97%.}h4eHYLF#2CEo/vO,8VW,SeߏSﭳqٛT>6bEH;A#Q~ /e+\SkkЎХo\ QG>PKoH.;I˩^q|UnfnDlnIR/G/3`x%OPN%7 i̱ ZV&,hV[* ؝nu XlOt\–w<ڇ`MA+a-}TĶ$vqH樂H5* ،E#c\lWufwhJDH%jt1E26ѰUq)X`>s,(-/F`e1xN>?<3#F1i4PtF' \ÑK u/DUO3#d%RUX#o.咐d6N`̱mQ$][3 U$bn3tTbiCW|ӿ}9B^U=m%+Ko~G4ڝ镾!ځpV6Vq ư#6ǵ%V3.AU&YhD)5 `c{ɺ>E`ʄ<5!\/V61*t1k^tM73Bt`cs H۰u\)t's_gJBD-HaPڏDyhc̦@ t[j IDH,rF# p3_KU|6~Qa ߺ(,zFWC- OkeGD<̺~73dr$Dž_28<:5ovxV /gٞw-+<{Kqb؈֍R/ze5{&qP$Fsp٣IzRb7-h 8Q,qMTa>mb,Sź] ]*4[l!̓ 6!%TKɳ_<޷=fRu V{Fs"J[%CZWT($GʑT6Q; (zחkWqDH:~:ϨY1g%@ R0G}2PpAi{fR G-N觃1P6 t(!{zz /];FW6=Ges.S9\_ l=9Uh(q141g9bg\( q|e^vD׽ՎC_;UX"8bʑ{McxLP 7(?ZWvİ Л@ TH"y!'(*d;~%evch:hi-VbҔoh5+-kpU.,z\TH("lMŬ&e\ŹXR$L'юb )ҙV׾8OǧqΏnF~P ks$T i^&Sℴ S˖IQFӏ~4կ"I3(:SM3ZڪifB!j̄6oy \%KTOQ5eMy~ძ i dCDx!nǩ2݆`2>lX!ǣ(=a;kzv\7dbR`5D"Lcy6hFUU52}Gk26=ni? H:az骐O>@8G˖RNWqKuK ฦ.c+b8x=0 #m0Mud k#KvPjAɚ޹5H\zw61VcAW%hcPt :`__k齀~է|=Vyƿ! sVܶ_1Vٱ31}:f=LNeMN̋Ƙ]Bvf U4(:sSav⾗4X*[=ZF޸Ď2WHz1 obY>f&Rq&U}{3bx黥[$h}x(n-#!RݭSk%m2zϨY ˂<+ n/`(Qּ%%Xi}M=}._n Pi+T\ -ۍǡXJlB#RWWk L} پt24o0%v5BVtU @_$} ̎a R.ܹ(q4-erO)7x< K=%TWvpl€< G?񽍩`~5dr.m"v{p-W'k{'|7lF+Qc7C5atf%j!N&{4D<&ȼ6OGՐ*w)hƤO/{X\T<:ؒt%[M~?T:gMVLK&MÏ+-FXKTaw w-[5:G{.vطgBzJ4`%Ԭ-j'.YPFa tH+1?:f dL6'I;r%7 vtS#Q\z<cX|qOp:0CSIIXp+1p&VSvZz՟ПyZw"W&w{_aMdxQVlhXrWSO .J孼viq:@[#QAxd#!YP,4@>/`i5'/\̐R;ђ%B9D]]讒YI }*fJ^+TSoUƄ=VJ~Cn-M@6n#Z\\z1IU|-W햮nwIF-oA\6:SzwRxU,;~2y+u:qo-&n%ˡ33w:c9]䀺.XnOKmz@U_wuFzJ[L]gs~|qΙ/5}gZ/ _[3!DgHVRE Ȣ!/5gI殮I> ~ӳ2ƅt kQX̲2%.J`! #8¥E xp:ǖ%b;}ec]Q0(ӾG,!kn:b1s7i{K>@LzO|$RA Vc؁XS,cPII{UZ:rEq?@bPi:yhKg~ 39+*'_ Ob"Ԇ]爚W:i[ (zwTS)lfm:IO318?yC.Q Xe>MUFM3ݜ]s`h Egw_ ,2u_8\ ,P+O&1uqpɧ)C\2z1vq pxrT軵cY{pw̹Y1._0 Z4+4I_;70k ެ|$IÙnX1  ݛ}|9]3YJb%,Õ,y=5̘|)8rڷiQ.~[oP& N\FG.㯔;ڶg*NyYuD#7#ʷuE\+/sd@귁eědQ]grNmsZ)}h!ܱnHZ ƭ~uL_M m')0/ފ[n'& 'D.\m fR|Eƕi~l$'Ѓc$!F,S@ݱLE'aWHˍ-PL6 k^jr"ΝsG!E,CS W~{^ &޹ F[BUo uEL%PMYQab o\A!1KZG4OuD7|, ݞZ Q^Co>җ: %0Ke1J$fkoqL*pi_3`cLWC1˜bSqcI7{a|}RӲ;$կS1z\-Ppt\ bclUMzIo@&\кgS[bgȬ죌]>gڵ6V$B᝛/: KnxMbޡ9L7ڱd[&X߫9>ڞ.DahjNk5?TFGIi0S >k{^SEWYFoGނ 9d>yД/эܾZs$kƞ ɛױx7rGV5Y-*sC0|u7"B$% 'tPV !A/O؅5D5.6zJ"P^CսQ 7KUjl2u#5ij6ɂ-/Y}<%Nb7Eo1q~xk]z+&Muj9t ?n d/ZM/]'%K }}M;Az/75'Eމ4(vK,zea"prs8o@بx?@s,h ^y"G2 Н鰚S Mrvl@;)Zݬari"p=1R*UPnM"I|bov󁳿TJzzn B 1}:HÚ01xmF؏’JV2s"[2U\ZN€:SWzk扸ܭ` GZtWurS2w4;v11F x~P)i!bh9Q1ӝr 4fOC"*,p.:B)¶7Kְ 3/9H^: Hh:@Sg2Kb1<ڊ<Ӣr\md^*9;3a~Hq۽7I읲.:cXoǂ6Q&)dzoqjs&% Vl;& "dV- cU f!u.m<βg/.!'Ne`nb#ҡߴ]IPlCAB. ^Ye4K:D'f LńeT\˄۹VZ旞Xݠ|T^͇ X[}p 'A>p'i_x7edaL(Ҕ X!Oo2>p';lBܘ)ȋRVեR*n=(=x L./hOvE*r5T *iQRu2ÂD[.µx`s_e*Iʘ b)#-ԑk8O&W!IKi3jo_}%iO #1 O՟x峜&6zXmrZ2yUg{QS`<;=ƍN x[g}FN 'byt߷f| 4!@xrv"+gӟxn$19BB>įl'$xCO.>8Jb@ǫқ̢Џ9'tÎQ9ۮyM>9H,ۥ(>|MpJHR,situID6Ep@oPRc2-M7J]B?L%t/WL=َժH 9S$]w ?D  (3,e;X(DѬk8d;*dhȿN$#~ V,m4$TWw#V(ѸL MJ*խ8Rg^Z&3L\Qi)V~rW-퇜wvA^\?Z9@owH5"\$IhFxJ0qt79ЧêTZ74El꫉Dq t|Kc- z)K0yC{=tujD'6@(N:ŢLuU 8Pn]6 F@^kl3>8)E(a f\  s|4n 60 x0Nx.O?X>Ehl9Ђ Z Z ]tI;r7Q+y)|=( +Hp;;"hd^spss[VvG"@$J~oMkxpD m$>VPbŠXUÊ]!:}WuWW?`=cr6vv{ jhPjcj겻%i -K2 iRSGڗfR?ѐr`wʳfXy]nQQzIc)PTd0V=5|`ZҼڙϣFx,hW!4/3@)u$n]}0ת͈z EMLV?2Y5hvz@?Z YEd* kf P[H,W#6B"cU>J&l^C%>p$(kCO0_``X6@q,VLbY͋͛}`0OlEF02CQ_Df܋0Dk&RMոCD5#9Xm<<<謴&2>S`.jd"5_?l=.aR8 샳us `a_K:zH}ȂD!8x8(ۗCg7Q#"魿Ԓǿ`S< aTTgӮϴ@ZU ŤۻL9+{w@2[g"'IF͝sX\`oWdfv'eDaْ PbB oѹskZ097$R2?rkY!Ū|2=?Aiųrr^eWYb>QRo;QU bu}ZVr/RQ) BFNF{0B Hy(AUPmƀڧl==H w-91B5=u1U*WG]x(_Z3̫!)?rˑ Qg ,vsIjkBCDk8l-4d]ތ=tL巄*S!-D$}ra:;ۊE/a@&j {#-^KdQg >h<żSmكdYXO  |Mm|6 F&rFS6 x狈33NxT uWh"n<<.ORHD5^ӕy@9%M I'dK4?ŸA.u46:!"<r3R,{Pf y{}pPΧ~'QrVhr%9mKgg:jۇEC#B1ʉD(fj#މJ_~~ ə%k1G_-<:ҴrJW%>>y%JewIls˗,b!څhbZtYV= 43f06#T5Z׻v6t,3Gue(qK8Se¨tt*PjuapFmmՉ)ߔNѝJ4L>S*V4CNt,F`C[q6K{[ERt|]⟼@G8ў~Z-|RIl5+0ϔvԟL{.܁<s I\7:+.O_jj0E5ƒ%Xk2i[1PqDRg~-|'dA-dI*m*6 Inbgdߗ-VKм3[fE:rMh#DGc7H2/”W[[5C&KDyq|bRF6@{!KWhus_c:V%co/R]9s46_*QŪX둋3r> RZ&Ѳ7m/? %bKrI©5P`/c> %ba+deWr\Sa"YNsB׾^{aj^"iO y(,4-mzP̾\XtDUy~RaVdθe~GC7%VOߋv#D28` 7ndK5$v/+[@H_0դ ت3p@jo+lJBJ`6l u>ؽlP|zh>9 2Ls tP0p!zmfw68` y10;X~+^6NM!CiV~]ԮsJrv֯#D R؊rI>4ro? CzWNۘdRgrPb{9;aIrDk*Flw=1.Hwi~܋R|S."BNGI\ՠb)[8ȸ&C#] ,rǪrzWc5Ҍ,YsXV_{NۿڠV򭐋RFr<\ძoh%v;_4Irp!5Ϻ4g~r҇^@9a FT #*I8fkrܧEz+R"z+:DN y`!jLy*@!NY3_6i# &߬b^*ơCeq+"Q4•h%S׉A7:jdŨu;\ұdNqP) {GHכ]GD'w;=in`D!6a, SftV\;:%TNI2caHToDe1GӖ<ʟf9?Jؼ?f|2L!{LiY;0q@ztݧyr=8;aDK:OP0eDkf&L%da~ ػ:s*iBđBqf`6 [ q~SX&nT!O\6XuO"an4*(4 4dguKsA۪ͤb:O^Ԏ1wrU?"uĘSIlv0mYXx@#->A*lYc82)vLFn6M4." .dcJw׼0eYtX*24e 5Ŧ w;gWWw.vO z y @Qe|eNTcraaPln$zcXKɂb Q͂LBb9YU$!KK0boPem訅sC=Y.  .Af! cpj-vvN; ag[/}ɅE9o76A! +oZ* RƵSW$jVLJi4Ob&tѵS/8nyqg?)8(0ୟU$"c ?̕9;P@zƒ"贋幀.O=Vg41mE޼ i[-CF$Hoٍbl=x /nA+#%ߪSؑӳ%zW벽y9OCQ4=$}aMdg/a@/Ơ'~Ǥ0q",(`~͵ĶNT<\0H[09ņr8 sp0F]TAUm2Č/T~2(6Pg][h ~_+|b1fRl*X}l ڸX|eRgB<';>(Ԩ|}wN}2vtd9`|@Xf:l3`<؂G"79H?&X @[9+Kt~ W加wP~{`a./ߙ|dJ>劳mfB9F&D!H `s1t$V 81П -Ƿ~tSJ.o^q4]4x&1O&_Ztlc]|LHrDzѥ&අ4u7ʥJG>zƷsYzz.2p3+b3D!QwSa.۸cO0h!`5rE(hIb 8t3%?4Btf _eitQ^<:>"2[!# 2HZZO#mWƒP})H."RLVHLdeYɌ'Oc7q(ŗZxY7gIkj:"1{Sgb+89r* @d8k7a<1/~0S[H9L`-AB.K{Y*3Pj^'|˕6)I]ucdV m8.d6vܛ 鷐VPIAi1Ø#ㇲuYPGV5R;5/ԇƋWL1 rPϚ}>Ga7ڿBۆn,lFk/oG`I U;?cpWoT7|YK3^|Y=4+^;3iy2FFC_˹$*K%3@V#yqi8I]LarIߜtyOFkc L~n L' !F$7GRjvG\@IDme׌!uQwQ05fx$W=q( cc_}-{j~梆+E7phDL.*Sޚ :R)ȳ:qt10,Wu vϲ0MSx6MaGG6 Й3qI !Ū~݊: Z oZ666Pʎ^w#OJn]^Cqf,[ՠԩ[:C`Pd U^ QVE2PP}}@Rj{H0R鱗qf,vro9`3p'P'E%ky$k.rՇ'cp>pxJQ;Ãt@]Նw˂?nnh/54ꄪda& Q֔ }aPj} GBṚ? ZQȈ܄S$IXV8K|(u]u8°q9C4r8M+5 B{ӱADۿ}ZAcU*I:c0å<0m}aHq#4-\fp.}!w!]USRJis澏I8nn_aL}߳@uo :zQ6PQӽ7i O&Iƻ.6Y;_&fz'Oa;+L@rQT+k}lP!.s.$6Qo `SIZ~N Wc1wr^+oboB}*b85ņq/JPF\шc^Q `;UPFve.N.w ʯ 7~%}A/"I5[)<;"坙lQx/[s*k^I"f$hC@CCXGNqct6a tc=\#ԈHB8ZUAd3 ̦߬LB[U0ˏ-g쾸bK(pM@„2ˢ V1fɲ?ʹZ]\hpHwfQkK e9R~U Ď^>I?p 8my9caDj J22y~wGGۖrCKe%]cEiһZfy.%e IHlA43,cq,;%$NU 4_y;9.&ck'7">S[m.1`eʾK[{q"0ERCz 3~ Xo|x6?!iT ǂ8iM}ǥP>$-[&`,ME0͉\#A 2yYXfUE][*-P L)[ 0j7&Оa ̄6IF ZͿes/3,٨lIA,qkF eBr}vCz83Q?-DWJ4f/nX x1fqat.tAֲч6#ńS*S= `mF=Z >93%.FCF]2Iw57뙇eaiO<~M!#Ɣ $`LxLmhQfXA&vӈɬKջ|HRy0JʸqUT~Z?C!ouJJ+c );)[S۬7ҪK5$KOš2al`O J| Mln *)8;tk7pk_$K(0Q[yA=nFH<1xEҳH9xsKA@ZL^hp.x!ģyipx%dٛʘP2IEe03#5↩Fx}rB@v|wWVщץM]WUv'3.kmnOll]!{uxztYP5*>lDZrt…J$i.[Fuަz%ˆcdW}CͰmRrp+[Ep%J)˜e'o]`XB>͜ P₼I*%+Ss[xPyPoۅu[W k?r,&a~UAM R t("=28D%ǰdwI`z>ծ]Г)͂ԴS^Fʕ?--˖zݰYdѵ.|z#XpNuخ+Ԙʫ W?8>:Oiع]!:1'ZN@k42a2n*tz6\2t3Ox Vf\sA]͊//iA*FT k4h 1DfJA5xtY!ƟU,\d'-mՎ GG5Zdl#/5_{5X0M@k/)@k8  =KkYʕ"#ʊd*eB$Rr szqP͸s"5̚;ts[Aw#]N3/yy/%w?$Xd4^Uν-no۾ww**羆k)؀./;̙qs낧p t9r\P whמynYO}ǰLtřHpT>J#Ӑwh;{#.&`jrowoi|^'=0ԕ:G͜4^fVi-&lShJ$K`Xr+ r~ #~Lj2ŨW+^X޵ Rvv&r%;"bI.uOćڳnՐ4ށ=>Sxa~} $fg[Ieud}'V $Rlq4Ǘ m}2O}ɝIU*[{Ë [c-{.Y|'5@q:1:`xQjB1+*SjgH =2c}G}zE灿2L~4,O,⭸𖷕$q9;j:O=F7ݶ_kLwy%w)K sT4R j 7UuWugRK;ػёJGfagZ4),4@)^µhs>yfleNU:DI-~Qe>TUOZ:HoF@lfakڪ|uxXr6XGfv9]գmhIҥTv؀8k\t!UasSL(*%t++:ɺ"#y^FpKlS g;¹ x+ j8Sm/hP; Ӝ ͪu s|qU~(\ fF2=Y;=s$g+lg3*=`Fl~_Qi}KL\xigKema>]ƦI/|lLKA @-֌%}iӔ^;eUkU Ub~Ĩ1Qv)0|9b>)F~eo" )>N>{KVtBTի#sz?sɺ"!Ҋlgkw 0ɞANn>omL~\Qi0b6ɂ}]5*Fpk/aNyA .Bm}p\J^\Q7~TQ\8&SUdP奷ړՐyA_l̓șJk[΀7᷿I +Qo1o4^,H}nCebcz< ~s0 u.[(f$?&45O'e*>Ȣ[c8X"uՋ?E,d՛Z qHٺ<E0aZRɻR#kϗ"r`A;QGtX`oMlAE>ӣ^t,#|s_l2NwKq^0]QtZVbHw?}0l? ;En_3l&@&߸PMinkh;iRD\oN~c^>J{}oPHa!&r|١ rѼa4t)k"J_i@';c8Z󖦖m*sSKH>ϟ-4J%Q01y@HQc}#ʐr3 sH~d3WIu08Qz' + _V o+z {{"cѸ L裝f)xGWDs&Xy%P>.[^]UI;K6,Frz_8gwx'5$ƒcsi'Zv!vK`-@c˞Iǀ}5S)ȍ+TI!H!6CC0ڻSr#wg .jIe׉ƭ7L2E Q{AiI*F7I{KPj /,=k"wGxzzq ;q{#~ǑLەldإ{2=rb_9'QA!+ϩ63^7Q[i3YIT(ؾ@B۹05ys̀nL~pONαb^ ̃.-g ̰NjP 9PU-%7S6؃].6v} a0t>Bz {Ntf^6`?dXZ;z>pO I Lp{`%QH:!ƣޟ ˕S2y՘JiǠXBcWCךJvNp؉!˿6uoVRmm y˹w g "_=drzI) e[I7{J̞i7t"@ &<!5:$,J% nŸ>3>5ϔA e0Ac VY_ x>o,0~5}%K1A-T&w2_&qw+"!dv}nyTXݺ'!@xk+<4Ô{d.Dt+O%M`Ѹ>ޑk"#NWᨢT[ :|`77vf3F䍍;#G O.%-Wrꊲ1:beAjBWb2zӚ(ٻf7;/Zur 2r}3<0N˕ ŨBڤ<yC踉M"m`faa9mr(Ëp>E5E߱Q/M]؋..KQ}][azjɰM@!4wq *p?̤z>ݗfazxnf6* C'XlLYW1IE NXە&BһAr0. |#ݖiv>4e/O4L~誰.9|ho v ]i/ӡ4a,٦(|2Y|ǸחEEmM;$ѦW1@CW]݅q X鄫iZ;ݰq^ou63`3[Y];% _ξ}&VYanH@v QB`o KF#Vj)VMq '7$Sމūa8'?AA7Vȵ:7Kq)/3n7%h~7s-ɂg ]} J酽0 CzzyޔF+5J>$6G NhBAdY./z3B@StLGy;iٟoU;Jr¿&HOl (ui _. !LGxj+W?X1݊ϭ0X%p.@aRɖcjV  k=z:gx{TG̘ ), Y5DcE /!J=ƭ='%課c`Lgl:IIܣ8\&ۏ{pj1 "?cۤEZګodqF_LKb]ҫ_,8%Wg5}އgOD #ұ'CTIvG4,v`/qSւ`Ƀw'2]0mUp,VD1ymճ`]Qqw62(up!j"dB 0ڇgK3UQ"{Zr\CA&~JѰ&qjĵi F?x;B4h(|I{230y嬋ȜSc^ u:T4MWA+xz]7(`I#,,O)kn)K>GNY7|hv8.4OU'Cz9y P_r/5NKP1NYӍc޻Kx5// @L.;/#C)+K97?L,V. ufs _7\o"ȀI@74RV&H=dgaxSX6+0X#b9^Crr/؎sgެg].loޯƝHj^7:p؜S#`;tc@ -kŷ(ZTOzAC rm4r2[:xɚ#;7&`GXV>ց`V qGD[~Ei%pVHɸ0nLHY;((Pwcfo{)Vkd͏}\Vێ(m-8$FzTe.hpx9xҨ+0`/< ##8ҽ+ٸx )Ҩ󏪩hZp~{>!O2zգG/SSsa2+6aR夥 *YZ>YТ8crqE%<1`Jx} NG KxU so"Mo;̶bvkO C¹"u;X D q 5'~ݍ< i s}Gf}ED1wxr*nuɭF8ܯKh#%a?^E+k=5Tr\ /'wЋ/ax_$FES8PC^ $яO"3,6/Wo@lu~D1"g`NNNq.) 8^ ᱀P Rt:|=V2065D=&mKC%A VųHcҁ %"]k֠8D#YyƽnHMGa'Lmewr]YC)-0ܾƞ#y@x1]e*)K8=D)c,Is7Ǚf{WCfI͕S|#Ldx w ! ́nZԼ*m#VĤ}T0{lmb:;,=ƫ4ik^tphK!~W7@~a5ZJ3 +P&eufK]W$3"R#'-EA6_HjRf2xg5 ccc6;< %Nu^y`Ui d<aϊmإ %#%aس]x"1mbF$RdJitE pquy/,NI]" X[CS 8=N`t,/x-h:;iH7QQPó<l CNߧS2)4\Eu |5?j҅%fB/*( ɪ.of@&u~3 qrk{DR_92% mb\@r2K>,4vO 7gB/EF{Q U1pn^%%ʽ^v?aه$*~ӞuUH%_dMǏ9Cq4T7pxdO=@zxШ(K1f՝W; w/- A˖L1m5MNiLIo*& >5wΝ=|2y] p<IJbmp|F Q6pN/. (8]=0pJ[ \Oi&xKYjDmtPjǵje/, LB aصluV{@Y%3x[2~w=,f,0K#٭`pα-Ӳ=]H!ibZ!boC(/hI,bk<+ Io+M3Rc.vCˣY zy+hjĘBqXHSg-Z gsFmAJ&Z{MKl%4=e]¤/jNy#إGIuY(:WmB}ke)l(0Ok29rRf*>ߺ;?ʝ U{6V teO5 LU$Gٕ4C, dԃ٥_02G_B$oQ7kUyD>-T!3Sl\*+(#BoN&bq积4)b4K'vDP0fve%`xo!n~Od5m~!\l j*H)\-3 .0Of&^ѬM+녲NꈷMP=|UѼ*:ɻ{>4ZY.%m!ytPK>CPVr::Z?dڛ@ὔXT_Z0Od)w;a{qeQqQ[7ϳ&,%mNFQu4Een2<ݮan8G1 ׁ}\L&KkofgFj<!h='+LsNq*So.ueҳj98H)՘ۃ&CD'{pQc0n1ɻ/яbB~ݳGRteRD"&ww\IL.v<;Ie6-5]#, nz]O݆2-&G5s.XA([ oz2hnУq5{䠗ٙh,֨Г蒦~"vfix o|K~Z'wALAYwjn_ow<9$x;+'52OҔ{ H/˚,$YQ{@`o hj[ c~ ޞ431 ]z_ިDorLb{Yf|bX+A,1.JR!RcLuQ9r 78& n75׃~ )ȳO_MeeFCx?^IA}唆J~ ߯ 7nJ.ah\,`xR2gT W+ s"kinxe1P!cM m!6-8HO+ӱ^`eU*V. yviJ Gg/y~&Z5Ų*,vFF[%1xx|1 ҙDxEU5$44еW'l@!}/^q @MH> ЂmY?%wժ[lCJ7{2j{BHR Ɲ06̢h\0Y( ՙfu8i\ez@h=Fn߶}t;9pic\~zv+T^ <E.FZ]k ;.r?}Dgդ4?DkMu"C莕P/³+@I z8y6GvU c 2{A/ٚ~`(,L - t$gpNX?WX9O@{$尓*w<aqHSm*;`;ny#AHX%d7S1]r3dړ^1f F'+îz5}߾Vj7?#e!N0Daf%6@Ah#hiG}/ ptf_O綍C$^I߿^u$C_?&e0D{xh-hx N.T5"M\^Dr6픣_X$w-zoy˭s,A Q+Spn2Bc!8xg?I!8> &m9j̬9|vp;XP͜.qV^1{,P7Zޚ-or)e %L ƖX\#[EGPx> VUVX}3EBj 6hUY.+aΘZ,*%J `j7js0˙Z,EO}'5M…RR{29PUB!sOD /Rɿw5j ͼd?y +n)ڳ8}K <@UC8u!W W(m 7nv̓W[ 9)EJ':j#*x+6f}e/R5qs& 3g$nn7?ˤ4ה nF#Z0ۿ,|RT52U_5ty}a ӑGg+]9DT_N#EI猖KJRWjOR`B q:H(EyWR^Re"5amزsh~s q杨۳[(K>d_ DhP0i 7/V]ǂ;AD9Tˡ%!*=EvrLm'3^祮h5~ jQ~0 <&yi 2EoFN0eI` Ճfӈ,zоb8-XtJEU7fp2N:FN {CW^z=SrzwcMRUSV;s)`a8 lU+g,QfVlbͫ34(wOUTӻM{2mKo]F[pHsY?E9n\?e 2-m<`FIY}'K8ӵ^k{听FTݖ[CI/嬪a̽xذ3SFS M-ڲI1$q t!Êil˃}5\o`#W^R@'AY0gmTе.`I쿜;yQZJ(J[]ݟtTi 7~u_3H8`(/3W|?2@GJ_۶+QWN~ LAW0H)J%38ʁ\;yH_ 9 .rqzBANj2ئ\)NFꐎ;?*Ja_ZǟgIaN.$ t/XP4罔ڽ:@BrYN[}7w*݂fU5 2R1(4dc[Gpp:MlLB2 97٦ZߊebFɽ+tѨ KyG.R6@K1I/o7ɒF 8*8!HrJpô=\n@=ϲ$Sk"G[ ʫ #̺? =[>JkSWק{T!IS#PXDTHTOfהb@gcL>kӃ#;)* z(l{sUCiw!*sy Ym<֗f7ntەّR!\I+Uñ "4Q91' 1<`_ZJnNBikLQUQMcBE8)> /ou词9jz}ƥYlY'|o4<Ӻ_q5jL'/+t>읳`Ύ/E_Ẽ~p/=(6}8$> >8eD ؓW]1S.jLg> ʪ~P3XNaPks<q ÃآQɼ6!.!dh37TKXL /F$=f܃GLHRbXzp jІ۶/R"7p!g{'λ̲KdR i-rɷJbç}X4h/öcOy{%r0 ؁UažޙNqC9 j'%H~C(VW<洫ͳe=ȆC tzU`WXs3*!p/{@лHq?Z<~d{Lh)" ;I ,$G'R7 J!oE9m* _M<^ :M7` Y  !>r˨ *2Z?/}/UE9P tJ+)I ҅Shzq /!3 P ӈ5i߰.ǂ+bx%) W'g(Q0yjsz.s)RxbD.q SnVy*yn.åAH젉Ѥe2iGFd(?h6 pTAT!)m}*;6`B&2'unNz5F8z Js` 8(d  &~3a% ޖZ]LA$) Pf4W$[6hkI6ف"fnK>%8fk)->ZBIR J UR*b3; j kdlx^퓥L o+e &1d~\ U(x #Fb#wZ\4W6nZnN"Q]iumjEX\9% A]w,:~u_BpYɧ+= kd?c;V +l(ai5>KIZE4MɈ` ! u#'ߓF'T2 z]&/N_"-(rNTAl+INEI08& *n'#YtY6VNqb9?[`Fٜ\p1 -=.SD\ SJהI5v@"B%;PsR P][Ww+f]cq2(I=/T9ND@oQYқ'ԡ1Y$z˥Vpp1m\(Mϕ$ފu1&-5$Ƹ7j@I>t&6'*Z|iPt!CyCudW~(DZ˹*:q3`A|KU#GF b,@+A5i)K'Ы쉈^HUh|%UܴDb%_cjw70=`Uo2>"Xwe16+7v ] .2viyHW1SfF9 =& bDnYhUUw{MLw(.َ=aaQ9 Xg >qJP=IV;md,,܅EBVTy̝I0Vܠ*sL d2:y B 2'?UEP.KQw4,O }.LI<+[a m7R4O= ) X?{zRd6$du{m+#q ~6"p0 AjorG0Za,1oы(Bthv?M2^z&Nt˦,'dR%tmYnBjc~m8O]*Owi_ _M<>q2P|]`-,lq?Z@8N& P0O?wÚN`wEw@=_-f8@6ѱqzݗƹ3dÄP/3x,G4!yW hܯ=}=KfLXRzu|=/&@SpF{xIT;Kۜ㐴++"OP-'^-:~6dƮ&X48B 5&B 'iB@WP/9`n?71nJ{#wbwOSU&`I䶼lm\;~fe&V 37u@ T߾:nK^P9݀Z7T+$UV,?+t. b2(Gu5`#k#.3VJ2 z N4 չ 2kYod{BN#D^GnBeAn Ø@&Z|`ȶ o#ڜAjPۜ 6oưo!g~ s[4ߪ6ੋ/F.{0k.{`DP*Q@Eyd IEdd]8$-fD &̸esשG+7ieHz)Iz"z=ΆcE-4'2crZ Í݇gtCIhm%(f_Y^ rL QoSz X\n[ )Pjv_nC⋱drrDVGWxll7ACl{UtlQ}xV"_ԼH CΖ+=-Sw-UFpgTDV(ujj=;N( 輋y'% 4p. QQL;(뾥@*cHeEVҪp=]R7)tYVCD ٬.>/1CR8 @'Y3Au685lWM\Ǥmb ;@㾤M;)i<(Z#7$uN$4}iDp vKor!(aSF=PZcgIwplZ23*iTJjjH׏_b%;xW% 6?Oi*ATS@h4?]l6qLkȈB2V@nɒE?$6E<0h*hHLEnpims9!,UN8XɁ F~Y sn&Yii%vqO@Y$Ȳx | 9Is_X2Bsjf7ZB,T&ƸY8MF;ŸK.MB#j iuȿ6}xRJRShKR n^wϳ ,HE .Z}u%FVAw [S~+\Bf 'wU܈2,b'SvV =X[c5/X43^Qo$<ɵ-TOMiŌ(X0B]3ޡޚnY(`#ta?ޭݧT7(hpXY{kц-A]+5Sc4I&<(࣑)wJ%-+|CSc7A(ݼL$)|eOeb'j*, \S)AaհB-݌hT(W<[Fc&0@NمU]SoퟝCR"n|xzYYlř⁻ 4WGK*%+FJra<I`q|pWyx+bIMxol۪H2)YjZUv̫~+)PԚhv~KU 2J EGI溾iY" $"Bl#)zǧҷѶ[VXQS=f/W~frߢY io@k{PA+ ԇb TijheN<ş89:|e#_8:=:f4ΊX%xri9rU:h'LLLgpop6C3>hk=F`eI] =a) 0?O)4jpgOa:*&׎DJ+`Ttuam ?zӲ 㱾*S&6=㭨 TGfŮeFn"w_:]b@ An~>[tU.Sn ͧC,U 7xxƢZ؟}bwvƦR/h5p@r!wd١<|'F|Dʝ iÛBj_8!x)cu4̢x}J!뭎 ,-!)S!M˜NeL152lCq<~-L:}OQcY`hx$C)*neZʳwUXLj oLe9k׃j :oWŹ(Sf9PE2iN'I9ǗY* t* A@lrZH&ѶXGD+q hs0ZĸXu~T^JZe{'m <Ib@T({Ve2%!փi<| }cz#qicAo${uTaÂVd⍸RB>R{V4$rZ^sUv :ᣣLj5(ےrYz~Y2R[-~菂*ٰ>> ^O\n }?"{ˈ0BkY@:BM><VpYWyFl1M DE\00rv!u4+@xE7D<ܛ2$qhC#TO&J*5E5wk&2Oz]CuPMخ4jţEPE\e蘗~).΍Ӿ )u {/Gch<"`YS:, =o\J8:߮=up{w㲐5MQ?N)w8/ZMs0G/ɗ1n07'b﹏Gmxi(M BfRH2>7 u NˠEm%U:oKѫmrpU{Rs{FQ3Jdi 04HwHu G> 7̯ &ѿ뵟&@1ѼxB_CfE^1A2ʹ*1hQv8wV ֧|jfVG=H3,ttI뢺ع-! 7L9Ŷq&LZR$[hi6(rrnO&J|3&2BSaʯ!!lJ̈butڀp;KșcBԫlĮ ./)%֮wJa:5NljP{@Ȃ{U T$g-m6G nuuD=tMaE Qru8b!bt10sLioٹ)N& ̸D é% =mSc_H\i鉙e+4jc2̨fvlʊt1z:]:hB}Z9HՄ<ŒCk_*DPgnrn30GƷXeZ7$Ɏ8vhy_ߞZ&y]}&Cx<\̯#_Y0q֙ aiHb-;L*aj="%n al@FKK#F:.%Ğsɓ8DJ4?Ї43z {,s6l_%[ݨ?6N! ;ߎhgBoXSz`b&⢽0ro#n-yaD'w#{UvjNs5PP%ٛ{˒P?OrEQxS+rِ0K Y'_b!(~4u17d3|lGK.Ұ s]0Z'#+|cW P;mZɿ_s p%wSӂiY7 A)j\eTXi³Zzvp";<39ڰGioC19&us(A<1{mʆO%j>+ l'[mrd)sζ`ӑ+k::KThQ\Z`g6G~4MZm@,QIx- @%wC:.7e5e1g Zw`2nZӯT|QL{OuHlg9z* Ә-q}T.Y0 Z>_=9{k޾T3-kl^x:T~H\6ԀwhD(W 7'3T+e@G`6m,e$N92_-E1p& ;y#c{!dyK"AН/1$0ԏKsNp[T iB 8)Y]gsx .y f*;O9pd5Hsw~}D>iVZ[ja532P` SGX)o6o<ـw6FMBfHMKG&PܦO73#z2E]jxN|\:hXYVU? 1r1ј>BY59/ u¿JTwNNzCGrI\QRW-c[Q|=->FTv$RG/H#s NΫ%)9jZG ,Sdl{ǭI٢=5377Cy2Uzeカ}43 "nLS T-rX&IRȡZ8xtѾhk_*j%8IGNg{DqMS۸ȣuC,tt 4=8lQh~o!D"•H*%i {^ BZLD5>0,(=ElݝS蚷LaQduo>ԞӨFUmT3j K 9t:dz`-V~8^'$_2񦧜9>eX͏SRU}42R}Y<2Kܳﮌ<)G-SY9M~'J*o\ ŏr2·/0TMcO hi-K]0Jbnģ3W"'xt[ W!Xu!xsXCR^vP?LAnLzj/bH] LRc/4RąDϏk^*rT\VoI K>>iGjג(2X >?A"{pQRdr@h lu*!ơ}mŘ\7+:jm-6οF:HNbHQF.4rXK :$gSMdݷ;ϑ;1Eڜ;%^`tF+/| )OFNmny2GmyZҏ~H(z0k8,Ɖ;,tP E9A0_6XosTu[F6f]&!Wp`ouRX0N@mmdn{Jo2%NLIZ?aTlXa ڵ,j|f,aE+1:EٲVQr|j%dYEKQ4T#{ 셵3cP:7N`Z*)LmӡVXӠ#q :~Ud4DOc}plkI2mGڃwrGG@OA"wn%S-1n#y14#[N!;duOQ bA(VP swb=~ tZGx!e6 6?DŽh'5@ޗElh#%oTcsӳ՜_sO!.tiVVSDdI~mG4 jY"f='H @d5&yUW.Zh, h@Ꮿw2B45zXQ]ݙxW'Et i~#+Cʫ@33"^[A3Ҫs`ʨO+۷H{"FJ0D=/0-eN+%r1+X)?Jگ9P^-ÔoK,MMc9#R~BikBX`8NC+J?l+w %-ѻty ¥nt}E<1su"\ҙHw#Υv*%f_䆾 J2BD18}t]*%wquV\¿19Z7'#Y+6-)Dl'Y_Lbos38hJ\s_t|jV vVbKFڊxE|D'FFX]G](#j`GДn) F#L's !ĕ0r=lҦ6׭ VR9З*XJݕ u,{7VU`Wk:eh& ~xDUA1`,潻r-[;s%jP.kZ><׾JG.^UHS ae3X-Vƿcs/h`{u4G|;S^)e %jԈ~luhe yـ6 S;rP$z'PX\a,t* I=!@w>/r0\ Do X܊\`T PMȆ:[UXT/LYiPVy%)L{&5hʒKKyMа"rWX4xr{ѵ;uDLPN5Ν|tYY6UJ`? 6UnB*/0ZPxNNh4{wBE|zoOr&x BTȹ]oH0u6ʂ53"|T8Y6p>pk/xna;3AƱjF@CL< ئOw8Hӻ%) $2?M&33_&Bpr5P{aQWҴ p ڝiE=OTwFKYE!Kv\71HK@䃡80m3J 7mglM\L.}B"ɔ?QVn05KDt41.1,1Sad8 + z5I,o)WL>_Xn$l6 | dٗ'$fy+cX5c@FQ <\|OuÕEex1a7X?a#?gq0!-VḺd>*U_Bڅzs8LAwvXSL5*=qQㅇωL|It'aǶ?s3dL8&߇ BAeGqEKr++x YQB~<;?N?%c^{plQWS-_c%rVmŢ`V᮫W75>2{SF:]SG֏b$p:gL*uN /0Oc%Yf/\ÖF.%ھw*)Zǩ+H`b0TkFb2gWCQм0) UlE!A_MWG[iBK[@W/8l4mɛt=+7a7a K~t7g:ee[-5_&!G]`inGE/×`83ar[AFЍD=}tc:U\!;DbN`ol[S؛e"6,q,N [[ܨ1`x 1BРE>jAdVKq맱.y@~IJ?Lm잍lѴk.CYNEv"CCX5lr1Vb0ZMaCq`CԚ\tڑ2ًJY)է!QW@@KÇQNw4-_y,L;QQdFr/ݪX< /Ti*-z`ہϐtAv[VKXUg{Oqtt] =6ofWl2 #+Hܶ\"!#1,vyJNanݍp4vHm1-fgmܒ=:&Uc\n94aѿ6T!|ovպ2Y1*V@wiܴOF+y|6<ʅM7%騝>LQ#h  nbFϬvg-y?|1` QfTy+.yY'"'iA=SNIʃ\ xބMJ|BRӫOBeJWju ӗ (Ss~4^ε?b0Zyi1۲iyvk` R .q&?)u$Kl9bMJ!YbNvJTſgo\[c~+ ׬qx%3|Bo\9A8xk{)@FU>CE݉Aa4ϔi,DyC|V"B4>G1_I>>&c‘L`2D.۫Uu/,R?;*|#90ňn$9JRLC^4ӞV`G+Ӈ̛l`Wֵ GNeaM1Tcϒk[*A.(*5p 'vB\Xźd?e K~V3_θ/W{1jo@\ (.f˪"':VmyOlCr؋oda5]kG[rsI6ٺ '<·k|8\3r{|`hP|agMu5nR3r$G>縘Wȣe"=>"X&/ 緙-NCm0c݋. [2EpxN{!a6ͬv qA-FˠQ2PI*XBYs"=Bo'" wO5!oeknРNPJ/9}+9JJbߨN5 _Itm-jKMU@ʈ`z5EAz;{M3GAKm jˋb?'R'Tq]?Jib+hŽ]8T_?v>j'.wodD&gw?%6vfikG"ʩ wӖ_X_,5G6%cm*-n>7#F:P*ƥ&q7m&rvxyp啀@pk+] ¯o߽ÓE)Iή?CAd:m'+s]I rGQHw 쵡a_t40+VFSj4Z =!.i~.nR֤t 2 E< i>RUZ;j&nmwݡ:ѱ3W N#Fb,* QU6%O74 u12D_/s mO Frͩr K2DtF_,N?ٯ+O U㟀9/Y5sfpOz?qGƛKlL2(YFC/IԊ¤D sSFV4UwV;b/a L% `0]ri)8_S #6G$;=-  ;ETxTdS[`PY$"ƄVYY27k1||!m)ɸۓMKjOn¥cRRrg^ )Q];EwCڴԎ2ŠOJu~9#ⷈtb@(xҷCff3i_o,xC78fud=y6BPX\_@RϾ`z%U]θ 03"c p*^xW[߼R=3elRH@ï[򼾬4xu&1, ]( G,%<#"WM.j @*aB }?2cF( #']&Yt ,6/+V+&HtE|6c¶׍]] =fV='}@U[T#)nD]("DQlJ-yksOj13_\?ofE6}nQ/2/>s:qܷ+faQp' DF-儆]ݰj{oj7uo5뮧 `H{2I9fnNAF^ԯuX HiWb6j>`w:m? ˕1s^SNjQ!zxcO7Q_9`CˏBBE_6;ϹMrGR$ŪT(΄PBfZC5͋qڧ 9|ΑvGSKv+>Mqa7F&nLO(oy,ƨfctpx͔N^஀q"Ζ{^j|l,7sƧ3M3!}^KpZK%xwF!Pd0L,o-ܝ(!H}yQVbKGCGa-k~lb;U(542;~I4A5ɱ4qsČE('Mp2l5Vˑ:$C+b\y%ave(\aji d W x^B*ޢ.kьʕ:\'<mɟ׳P-$#*ٲ|"9߯?T6}Fy؆/7VyßG9l'yV4Bzڠ?6Jm9Gwz#?R8h}s~&ӗ-kgkyK8WrXPCAqY5yZds!js jRt^x!Dpu=!3׷l)*7̤]yR%lEu&7U-4_PAn:+дǕvKD-vwG!mؽmqR=HZDl,Q*+zdSXֲc:a?`CS+%d>v-euYH`Ű7vHqkpYBuZAn㽵D y *Lb;e;lp01fh#3b!†'lWO~Z AIj8♹fVq q:mhMYJNm]Yg\ț?SQ"YFT,nqr2+JT_>I\Dͥ tPlU)zx|d? !+R=m2 ůRYmsK/A !DmXj `wV]m(  0q+IMTV hi1``8iB Hp^p6mM;n"Dk7P=8pV+]ID]"QB$3ܴ0ޞ|Sq0$ǞU 7]ջτ3S^GnĈ$QQȥs!AtЯe{ׄDI =qv*_bb}.(?.lsp-EL'dly 6PRpA,ֲUwdhk RiC"24=Ǖ[2iw)~nw; oIItM*yH9y`M!;ļ*:O mVG%b@X1bs9"ZƬ R!6CƠVN/ǟY:65 ñ9 /^LʎtϹR&(qfMEtzHkL_N ޳H8^?CExb܍հM4|c }z~4L@43KFVf(h/9P`6,g.r5j݂{.& @UTPJmnv·Nv vu^iʨ2FeSCg>d7LZ"liif@Q/5Ck#(Js$[01>tf3j E&b oYCJ1PQ%~Tokҥ79QN0}3Oh6f;УbVEhG 0uh K' Q4܊ `@tK?g&MlX_Wy&#-.&i diMbۈv>e^9_SjraM[ҋ#h?I'JLje\SdLe%BB=*$~ ~m)/WgiKK蛲uOWǏr$(e =hӪL > 86qȻ|o.xXNK8a QZF;q!#Ī/ñXh0ShC$I/$t u;5?8 )YO-=w2g*'ߘ+'_7=pRn|['|a0wRTo5T ]dG*,G[W=! ]R"54?<8xJJe0<O};7<ړlF$W5ۻ,scxۂȿUkh祗fM))N\5ڈE^  ږ`0h* %(TZ!o{]l6epm ͈x~IzATO43,s/*6rE[{:O"0r ]rg\ߒhb_:Oϕ,?aT3ل,aȇ.S2 ? LA"[:^lZ ږsKTKQGw+p-+0~иgYmćV^9ҎunݝF)ۄ QHNTy', ti5GZQz.‹1P}FH-@TVEOǏbP)%#Zse1L?/{b\o"RI%_UTU&T;O*x:z"8P\'-Kcq4\pn;%CaodoО%W1k7~4SW%~94_hܾ9B7^Vgyr'yOaAI0a#C_b=[gYynKNo-4 Xcoj'|>/Љ+˜}r:>aݘ?;]SdK0pU?:xH*Gf )rdx;`/+!2S>uWʈa}8Rѵ x1o"&X\-4we78hsbL-Tx wV=9d]w9V^4죬2A,Dm,wV\黂׫žvԔu!h0Lzy / *?N_(L%*/ԩE`?qDw/OE$ߠ{q3[Cri4#VP)` ]nZf#4Ervz*>=ͼ?`ljgL2 ABn𹠈۷bu~ KB`f[ ^MδbrQpO>ͻMEC3#YJq&ݮ Fݛ ̖ge-mNx>J ƚ;Ht㪽Z6t2 У0S}VX݅{#~ -E.h8V%Poso"@ţjpa.GJ0*bx$؈c[h ߁Ŝxec$Nz%6.0 kt>ʩXZx0o0}G٥OsW4tA턑PO\JLI8YPɛc.m?~0WNM넦ڈ2LY(Wo64\95uR?֭)z9g]52-YΓF}5{)N+P⌐ТK/d&It_P(Id^RjjdNv rN%_8^M1=X^0XEқJ3+ܸfĵp{4^mɟ\BZturKx1/u0K^<)G3£׭)c _L8S S?CO/o5 .1:D8HL uoyII;d ]ތ m^lL˯l2 5п隂<<|x;)Akp3L~GFSwu 5& _ܞ@ 6dSٯDьשE7wHwJtuCvwul+;ˀ;|R?`fK%ٱBVs5HHNrz' 8ϕ&+ w.TYJԞ-z68yAfc ړoNdՃrF&.KG.B 9/yqmUt,3^) {0 dԃYt, Ns =7 v%Oy-2E^= >e@l81jeC0ΨgZ ( qf|S'XqE,(Q͛t|+^3hK3sE^epzU B/3gr.cҙQ>VҪx>{lp;i0W}8ciSElа$5/..O Ry\8w`a|NPrS8dQCRaN0|GV/nd͕diy&7*5P)4T[{)1)/M`W\ ICvDu.ʋ@x,u$cXT)+\f{xEW6)w/j[(R2P1#`!k. EՍF!_7_ 40TR!JD (JZ5^*WM!wSw7}C jugȋWzj'l+ńj Ϧ^ ΘgV!B{"trg.WxG\9Uæ5YR%ve XO##0!LU#xxܞDs$V7S/sUdL)CѴ&MaOo ]VH2fj/IJ)HR6[R] T/36gfu&׬ jKn91oK{iIl1YVPDAbl ->iZf "JGZS2eߒ繦"ubwvo>} $=MkUSaA Rmlv;SV-- qpc _\"&=0];)Sd ԓS/==0$Dd,1jt-lgpԍ/2(ϩywM_/5G!gZ v%{̞M` k`ϡFÀ ,bxMLWArH?r] YG^B(vc0ԽV }y2ؑP^FNO\Uhu9#qh|8SSSm*1_mwBdq:zӫ% ީzEUee(?9 0oO&M}R(ak/*dvYu;eɊMUmI%i*5<MLsx\ÙTӁ3C.y:[ Ma2Ɉ`m%( ʻ POt)u5${zcW#|`K |1+  JVI[f'jX.>iW'-5v {C= |hsA&Iϗ]%7A'/#L~{|K ߢRIYϜ\:݄6?p#~>S$D wv( >7:~6_j4יi=Lgm] jo )wBfZw }s|9Ȉhvg'oIqqRO&FGƀ,O׀\r}f,P?|.`7FWx߼FV(zے.OƸDhw@,adiRS0+^_JNЅlWE}! qH\+gچ 틮:-T2˵ l{페9=Fg MrTٽ;vQաNT\ EduQ7gd%G\舋_c jON,|Vœ6l8jFpNfHBt+fKNRm.h|WRzK߄RaS¹1 V=@ӿ ajKp ^% .9^0uDdmoS'Ap;yu#)[Q =Ȉ6ZCƠM]\f+p)lc?f= XA~ܠW@V;NX({VkĎ#~&\2zGH a芆a?IQdld>('G ?gw?eFv]Ěޞh+V=iy- ~ 'дG0ax-eqksF Bt&+3dZuV+بZ ཡc^5k Sg c2[]e=OPm9gigzk}g6j}~[źqz̎lljpOE$* ]%g; 7/oȗW?5diB }ܴl CKS0qO_hbtr(Eal*B)_.Y :p6!"d\jc^X)JX%8(%?QLݻ3FLSz2rjrjkMS:l2J1v 2_hw6*]I Ѷ%{Ed6NڨZ5Q㖊楤@RL췷_o#bŃt}?zgH6IE-#_w/\ʣ(K ;P %9A0>(G,?,%. 8>l1GV0/=n^QKx&ؙAa/;ccL+f1P/iop2DD'-f\"L}KZݖaMӦ' iy繦 |[/m3wFţw|WǤ^D/(ROA.gQ" \TIwޅt6{sQfGAf`'D ]~ǔqv18/pj2ACV黤\&5hvS 7\ܜ+TVҥO/(wuAMAԵ'Ň1ӝ@BCOf3ͨG[4%z#H@Ү^MZvr)T=ӧy {KP ۺ5{]}tb)NNۀr[_c7Um~d-~Z+.Cc> \ލ,Ӝ A|yn]ǁN4?I# +4H]}2#ݞ!hepɞNA%-h(I腚rCok76e |hB,Vi=βw8lIV{p Y޴. g~@5^0LTeG_&nknN ٍ84D_k/t 'T:~WeƮh4غsj?[CAhN:Qe\D/ )TR[ >ryAP׺0o b&}YVä)'6r# ,i ׎\U`DC0Z'KI;K(Z(k،wNw5>#">#MB! yJ*q]lx\KEwvco-m, 'Bz@LI6em [>m sTTz{ 06m+FT`ElS^*;Fk":s֑طU"! ʹkX7rg, nx U!si6iG?-5Vݢ{rp߬:$RL-׬x \؟ဉwb$ǦD_'›^^Ĺ@zD6|95|&|Ajp̻'_ Ka B ؿ#SbeLs~^g>^K>,S+,ͫ^t%3ݣg |jƅ"l2io6;y@VPn'kIBli M2cl:7jӌKv*Pƿ4,@&ZVTXfE^n\H 5NҊ]a#n= gn 5Q.R`[q\ m&Pu'v޷ud=ѐ5vh':tE=cTnB3OT=[ԽyNQ/f cU~ȓ=.8Ԭn> tΤL"9E`m̪n3Anu}Bt)`}k]2} As -%0.'9ߋyJ̐p5?d<~lZLx ">: @st,[kѭ'mfѹa.ma~ftexVUGn[CPx'Иwnv(3iDƯ/ 6'qD}9|.vԺ F>Y|$7a# -lg^rU~.#(>*5a%i hHU {+01$"EރNvV:a&%ZT<絅B(g[t?0dRkv7FF6Q+qLf'Y' u:jU*Z-P5')ND~)= Jc1pիF]j/o{CU3A–"Jg$VyPty)ppԹֲ;x" xnpW-{Qc[ӥ}\|E A%%BDp"bSu^N:dPMصtatjؙWQC* D۱ wG乺>Y,/Z83lD:ed wg[lH:oq0k|y?U9Nv2)g ha4`F9BE{ u tTJwBZk,wDq_> (6-\'EI@YLǁ*nuv\5=5"bN\>]8ZM \-e%3:^m>:W>-OQp `hF%%`sM9oqV%}gLͩC`zyA2Y7i}Xl b'W`?̣y@M{0гD6WkࡂC`W*w3x\ zWt۟ڧH$Tv *eӘ8WΑXjXb>Jq4o;+^Dw vYUqTsW*#mQ;XB^DԔcDTGq*ؘJ5i17h+7m;(:o菠yؚWLXpD.*)(_/G?s_^k~|@}k}S'ԔQL>tp_Zǥѫ<\kNJ@lJD2OkXr8qy}5ĞE %"U9pNkDښL{,C;{i5@޶+Drs+EiA)T.eL^jdoF{A/kOX쐗pu֢;6ys$oF2F*/诋D93OKp7|%JTs^;M.rڠ*=_P~o-ݚt?C6VrFpB  h%L@rP?om[6Qֹ_TWQJvyK@N8 u |D\AQ9JUH/ӈ Z#TW'h{C\pjh|l5]̡mHLN=(i]IwOnsso$m.#MUc2<,Llllm[+A`!=Q9dnX׸|9ٌT2=+E?6Y: 3*wA-CC_A ALCPǫF9sXE:3XD 9 `>U^C J+sfQdͺ \sm,N2aTba * #ᇏ12 -̽Jۼ^1@mD.)H2ƅN綑>лw!7y1Ey]2zrM>P.!oչb/^q;ke}M*'=Yrb}C ڈ6|tQ2]2{GsegqNjzb{]!gM!kC#PN)i_@=yޤQǃ^UZ+{#yZs1 BjCio=3o>fuNkSraa%{;nAy4)`ȚX &'D]{5h~zA78h ~ 1vkW2%[fJ(q3'Af= MI0}{ʨON飝jbQ*)*d3z>F1.w>ťI\>&F(8v[b5 S N4X3*(:M?lx 2O!Pi\vqӅ@t"H#%-4 ⡣;k-8ܸc:wiu1xEՓb^q{2[$ ՙ1#c,gB&69E(khuC>(z{ Lسӿq{Z6鸗pA~fI 7'ipӅxKrqcvv؊d@%|i޷Jeuxc*N-|Ӱו{æJ/q~xŶ@RBP/IGQiFjhU(Zeh@݌'p?֠Nq`0O\N}߇w2%gcjSBogr.dRg@ ,j; ZId4iӇUq͙q%zr@D^PE7 rKQX+2KFUhp vbfہ\'mfzI]oqA'L]D?;2$Bݺ2X8oZ {ZDɂsV ItkZl99 nϣ?7Ha݀ xh.v^e0[lDz:u[]m'㾴SզAgiBRQ>⳻'W\ϪBHԜX5ҽB=^6J3Th.g-U4*Nɴ FS"£k@};lX#>߃ f2;#?vWD!Io0 ?Ĉ ij>28_q'&2@+ϊiO__^c 'PZlwӱ?P~j"Z|Pd ę S'@;|Xяhk9{Ƃ-HZ$YE+_jsl}UkbQb敹CRS1uji{%'1*( YvY zv }f whێ jE)JY ػ"bߛ6.L FJ3c" kJX~˟B9QJ3S5Jۢ-=pDȅ'm]^OF}%/'-@U|+ A;ƃa-r*YRaw"lmЉXnh裴lp5`+N]/_`vjqS#`H &^D7,bC4Xt4GV"imw P0( mpD43}3''C&FLv .ӌOL =)86WƘXwu@K`tBČIL7s|F,@L"Hx&͜r,ԨbKtHi>+y,Sg!e' >oy<6ܟ2ae'GO2a@Fn~Ztj;q/C&eFcͨ􄇕Җ.lf"H2u<~XUAkzx{0^*% Y?<}b2nGl[[i!1I@=oG+yӧjY"/%= C5uFSڰ%حa%A1 K >m2w7wTc̸IjkLV'{٨"j|6ۓ(y}t 1OjmfQ\5F*#5x(qeSQ:SJW#IHSKfCI2] }~k(bR?BdN "!}*:"vF];zF^|Qjj #e潋Rb*LI i@{YI/ uڷ?-U7C1E NęU / jv9B%d&$sRtX752OfT'#nج@]ZtPef/uny lBt-| @7+I2.x8=$hFز{`9ea;=y"b0.<0MÞhmn.+0sMf@3Cw5n5FzTV? ˶@ u>"#9koՂUl屍 vHq!x^mc`"Fu7<*a, ٷ:W!i 8i`d!Ryzk%a>(44@cH57Ѩ0`AI~dk"כ)Ѽ^s$1dN oZ];;oݿȤ-[z[Wŝݔjt<c]2Mo䓛G36>LhF/x2EW,3X+r+T\@˦-FBJRױZqi=A&l8ZMRR '\mشݳֶE; ȜV3Ur"(Gů]!LV@ge`2=iJaq};c@FCH`ɀP[6Пq%˞2Nd )ILcH_ܚ[Sw1'(bj3x7rcpm< {!-rc0-_%gfhkIf5_G$b0Ɩ Nd$k>Y5/5ߴn a>?wW1%?oKP4`QcW1?)S/F!sWX| <$^bU-kg[p07@' LFl +W毆Xkۧe訣'(c-j}WÝ(FK~c>4q@8]2qB噤QJ`q~)#aO TKd)7 6{;U8E1RaOGjFi}6]AB'fQMdE, ^#b4o'͡EX C4 0h6aȍr3OH*V뇄3?Z(Ʈk1nnE~',? (uɌmx٧6|vT@GA+YS+W|P6\όZ<_F{grZߺ[BW磧G&k/Sl뉾] hD4+ w˴ 4?ll72fG"-iӚ1B#6VzsH&3x㔩&itU)>,I&C <5!kcwqw\p䕹}3yc}]QZʆj,1Uϋ.'>ӵɠҔPx=MĴCR[Н+QȘI^%/A,yrj.D3+=Oz $fuG' ݵc!,g|@2KV}Y`po{.TQ0C 6l!1"48Yʮ _h!Grzϑ]w uz73 tɢ TX{V/fB@X'7gU:EZ2ب~53 1Nmm{/)$0\ŘA2yj!4l4@3J'AX_w kV}VWG5P tK;Q`36V@ϭ70YkB+ ڪV:A#I솪k`Tpۛg^fAKVt:[q -Og#F uR6.X؋\͚1'A&g_%CH( "k^գ:ZN~F~s`_='ql٢L׾!|o:7wgS8޼[vv^L)ͧfY\Ss8`=zIP՗HDD\8o@aDRH:'{fz)?ظ%61\c~"-We6L@ ׸79ύ4gh2󲐄m"6̓0=c=ed+F k (IΤ;-٪]*/ */FO"DLt TH;UJq6 Hiq_.hKkEm]P{ |˵*UA屣-9, -$t8Y ke8[>fȹhòlaqLOyfGBxH~b*İE)H!`Wp1Y6$["Ж(6U:,5:SF=:\5(T429`= 9/ KȀv(N,`+%NA*@WR)u &!W=%z}i O> o5ݡhPʕ0sW ZY;B`mC3]xiQ - `K6qT%E&W˷hadV1?ؙ IIِq>J N.3^zSS%;9/P>@=e:\8a!-ܮ\:a Ia+߸ʙ Bkw`nug-?ALeFJ׼IFM[=M]EPg=feC$R ~ޫ)7zӀ",ρ'Ƣo>hza/ΛًcJjnq/%ZBܱ7H\I S ^fƯ0aP p.`#&wĜ;I<v `H=pa7%\ 2[S;B:xt5 ?QkZ >J蘼9=Kxѩ>(d>Bze$C)3lADG>Z2MXE3|3\+4범w~_fbpdaUc߸ r-Xָm+'ժ>I^Jr5eP'`.5?Fܟ QEGSV+**_W#&kGCx  #>MSus}'J{m{C2(@9鞘Y7Jfi(MX"JE^UBzp<ܶjA&o̮ iS? M+He2Kέ %AίHPߦݬa씃 N0i1K:~3K.i'8K6D5!w 1UC6 2 Ttcا<|fN܎^wCzaI*l!J'=|P35 fّTn !ay8n|| 9hynH77y'*w5PeKH<*1fzt>r{0vh=u9+s_\B OA}xEAaӦsw:?h 1#ؓ0a*m6ůHJ z[CO`Xfċ$H=A᳅ nШ>չ3p! ΡD<^, 4K 虺i <[RB0zѺ[ 8 <;AbMQY}H1u;A@6+Jޑ?Or%qU:KT,A.bp0&iɜ,uJS~}m?B\,'v eNC aa-j`Y,VtS^& z)B"\rC"Hs\=JNgP*@OZ׺9sTTzlĞ/yii2vmBHߊ ~_g vÄȦ;8/R ;[aO!+VU g_8R!"M -^|;e }:QvG"ï/mVu8}rQOjY@9%[ǧgWb*aѬ/NF&zpPD.DZG{?,rs<hVU  G!$ ٘D;8(Xb!FC-M5 OLo\?v2!Q1<Aɍ~F& {x/ PŽVvlUHRSk]X1"@Dʸ2y& ;td+wX*e81{s G!BͻM)Yc+W`_'Dl=QO0w*iv/M gGvOqhN37Y$/ƁlșD~ nɊhQ^d9ʪI ӷm)h9<)DhIl:CW+lq9U,SuMem>xjZWy 癒v9ۭTge\ƚ,:tnQZ$zڔ'J6 6.oWpZsmٿ`Y}a  -[;1PAY /lP%5$(Lp$WxI#hZ5}uFhgO ܞ|Z<Ӟwʺ4@|N~;dS C# @e"gC 9^fR٧P ްGs=ׁ,9 " TjUf_Lq馐kdly+[pٷm[iƋַ\yȭϋXT"HJN *W(5]ލ8yNdlJHd~}63~ >,s~_;? Lt"YwU]&- vIB=FӉzmU3>oƺH`O5Pj3xf\ x2aSpdyu@un:,-mTX-*~Yv}mCQ| 唅Jl@$,+v3V}V`8qߏ@AO6oBsWzkS_ 1aV!w;%$[ӿVI( K֍О$a\ׯFлN=eٛ*5.,1yu\ GOb.@9%ݨ2L- ix@Q'ټ$/2@Pҟ%z${Q5eƗ9ӏ.ht+J)B+bpmmd=y 8Z=^ұyяӛs3[)u򌊬n9P8 &wlhaM-]+ 2 7ߛȅvkRi.T^=?'RWFz2ϧ097xQ<ڷ{Ԙw)Ar:a6?:B+2:X/>両f@I>8m?z$,V_$g5:g!V0M& ,`=kF0fq/ .!&rh7C'R@h sѿkMԵ)6d!%%Kp&=2~es?օbeI7줬1a/[[DB̋{ 7ꟉheJ|XLsDIمdm "KQsK|*^^mM<))9%3 3):ϧg/ur3g"ԗ9UƁ  l8%kXNpR$3io9d:// Ur؉VEr@3U>H߳ =!n}=pPYV8"Zk"*]!u (}͍18(f2ڶXUAz+O=)ݣnj}d@&6MUzT.`\#0-3.ش0v9]W+ @N. Egg12Z }-u)Fd[iMCG-矞-TA.'YG9 0;}dv;(xs忚3TUCvD ٻnTEʹaQTjZ"Fy1gF8 ]xc#ktɘTB­ p =8yco)|6| ؽ/w r.Srb\ "|y=d x [|mm$95Hn- ~G 6rΫFSQ>I_Pߠ#yIS a!K(jW'GOvsE d{}b6|k"qSBt~ cU3f6+ 3#y*tF/mCZ7ye=@#>|.=@{&\]'nl'fA32ޚm1{jQzt,Eؗ|g8  @궣R4E5mQ.nd҆J~{` Xd<ꭅu؄jXa\ix .%Ņ|yEPmMŭ!`H$S( ̚wu7Kiݒ̧siq1 @^1!WU~q@#5mH+!FCnVxȕhYݔ7Qu'ގR1 $ 6l;{c% D\z%z}q%{^Uy{rEvBc&MbOص0{Όp[^LM:R;`E6#& ]h⍳Qh촇Hm)]+ 쉜g*="x/~of:TYNFaDNJZ"L&m6È1{F2[yq+Hq <)P»U020Y yb{A@F D>KBEAP1UAX;C@@Q%JߟXv't4.KTɯ{|-1v<.@yU9_Ε.Y)Vd _&Smsh0{R ɇU[Y/M34HTKy1+8._TVw4yv"1VARDc*زVF 8WAvmde;t#/REjGQIH,8KV'CJ{TM# M<(he^xz-T.-eHq~<2ٶN]Hϲĺݡ`6 _ s8TAOnP'N{|=; up5J3f:O\d]~h$ b}DZхߕ@ua+1f6`7D3r搐@!:ŝn l\ H5:Sb.i!ٗeWzfxG0[n36PTQ]prqE ΗTԑ˸n6acm GnhJ*E8c>iť dO|+(pToRaN0z626c/@b|h[_36WtSJl\MMRw<9`Gǟ3๒C Fk-|!bSM!ĪMɄgAT:!v7Me3Ҿ?\":M()5qy/RԵ.*U/+8Qv-p!XoY[fʹ:aFl% s#rQ~ b&$ `vB0.6x5)lTTqsL5dmluTP2 8[,w?llѤ7T8TB19h |B@z0ir['^ / $VzE*4 >44lx hr>OGCX#qtQ+d#LRcڱ܂\8a#K$-K -k!ZD=Xah9#pDN~z." PP_= ;iĴ|ǫ OLZN+ݚNci-va Sfagl?H̝tvz>:ó$rjH?ds"XH6teq? }}CbxRm@@C8d3=%vyXjF?/-B&Ԙ>Ƨz]~H #D@a7nv03iݻׅ~9s'>X& U ]we3:QӤۂ(,Sn2[A[9Z#^VNI/ .0#kZĖRxڑJO3;/ jp1O)6nwwēuA d^b ٧r{7pb;Npcrx3#6O}334JA򱫄d 21nn,.Q:.m9Ю8NkIp雳锒-le웴ψW?Y+*e3Y@ɈݘuIhlGeTup{o> t;AiD!I33E î&Nt(nQ\o=F{3Vb=.`刜9֙WL{p jn0<amO{ p;Ť 3#zN7mL^GOKP{Ƥ[i')XquR 03/ ؖmXӏ@NZ;rЇ)> **L8$c, \j6wߢE27Mi]򊆖*6 P21ˁI t54 ރ[R8+)ࣙwwyqx &e8 X4S};Q'g纡.T;TP2:w+${O7v*JFQ`\ Y/4 G["<Hl;X>o1^J^y#W:Ŕ) gs+L,S2_3+ґHla׃F ~t ^) |$QwRhZ+џ9ծ>*b4XfD|{B562sܛpڮPk3@[qngl2vxڤg_xL@C" "w/"q2GWs'XG ~c [oġ)ǒRu C)ZEI]hEh|s7°x$ɢLyYl 474FA̬kB@d#`}4}Gt` #!"`눠'D14/qk\:3:4(fs%@*0اXA9 aF5d>I/rS1ĴLɚe`&4iʦo节4*C7o}> PϤXC0 Ӭ1fe(0QZ>G)Oǔlxwu#G*7 S`ODSw<.+(2%u*"1xSD[,p=@4֖;MGL;˵jq`m趏RPM$@Bcܗ$!̡FlN u9ŎYCAvqT8 !)`V1M ?UaC]i!ra5l3|KWzߗF5æ|%|Lj#Sz03% 2Zlqv1\Ϙ]{Qhû ,-"m-3 xAJK\oO m | 6:~7q_͜stDG ݩvu"`"Ł>g3ݴ1NcRM#E_+7\[ ظlӯ3}xΘ1 ƹ(C ͯa І+GW~@5H.3H9˗E%b1 >'_UOzPPGޛS#,@.)Zش0D'tܺ<7:EK^_% :jCʏH5,mVw QつtP,[1JP4+jB:X9i2kxt=ؾ;pCz1_Q`=E`oɢ6ix6^ߐ^zqkX'nR/"9x`ˆZL%ωw0)#(SPjAT{%)q#$*NF^i祌-rk)ޘ'z$]zvh03MfԻaU h憙Zj?]`F@?m,ɹfB3hFԊc{C ߍ>2 6eӇ^TEGf+kMsuwݏ$HR ^,1n`UT*zXqĝY;EޘS Hdr6MSl֧!2.oi?I|T%ͭģ»$AJ;ɞfu4AZJD(9 uPzMgwʴRF*d|T}@~[v՗iT^ ⎼ k]I̤?rޜ.7"K!#gua?b5CDu]_9rT]϶\Ao3e5x~HENH *Pw^=+(3}\=]FIV~*1:zo<dd軫AB v(}c fOb;u1r\.Jyăʑf}N08܌&-w/}[HqwWkR/ҥM^P.Po7jDWvX9XM=fW'ty e 9 j$: E22to'?|O8t/- |JI?~7Ը<ezQmѵ58 _Z찃wK801Nu4a9?k}bsgC~=tVS*&Uo8~V}ixNuC rǜkN%3:!h ,Ka())]N n$כo.>{pU\[@1v+sdVrXy*=BgX$4y VȄcd^Udi)TjRM?7M읽 bӛ=Q5AݰTξˈ?[Z'<!+/ K΂+ M7<#AS\þ?{x2s-&v6kIxފGMq_ z$[WHI)B1Zb?xk_a] @ǰRʳl665->6ߞ~杊*KgLUԀ2Cdrb<1Pgʈ(Ec$QFwšfnRQ^6ܮ.]e ?6OKռQRlqF2mU՘a>x43moP\r ԥFC%gY Jŗ3}Hlzmm<jfvL1l3SI.ָz]V* |Q')%My2W8𛽂j0Ac3ryɏ#ħ2NC%ž~LYڕX="TܛܠpQ&He7cYԁ{O'"T{[eJ`!^*N+="1 Id-83fTU4,Q%a'({Ƚ?h.soNEح`-x4w e uU~EF(BQe˜WSVoŊ-)b%TWIОSdV0I27ddnVcsQ]߰q@'@f<}s ;$% pLa?wcm]/šNscUOxnT荨ͤ@1Iw3>x$JJiIpTgndzw׾jM^uA#'"M%[~`߽8~0Y~D}c{pc 6q9nTy.Ґ: da'-]Z#os? ~9 &4*Z26TêGN>A@Ob抗ɂQ7wSRͷt}<: vvt0Ԫ~qeT ^$A{|n(Ftl*Xabk3Tj-`eOA[Wo%0NC_ǭo5\A"I|:Ls` #QG ti,3.]rhkU9іb|Ϳe03$K]3+*д * mS9թpUA[T^z\ 1!bߍ m Ox06s8IZa(/-p=8.:'&Ch}3539ذhekEkWK>2 lE*#9}Yb KFJ8HmYgZ MblR /wV>ݙXlj+k3P1m^H%\үdP]`mH 6ęnsDlݘӰg2JVhR]fOWw@e)v@PJ6H' ?I5T\b)3;nKNLf*M5 W/ʵTɫ4.7< ͣH^b$x*##19y֪X6mJGV]IÏhGk1p9T~୴G%$϶()\ ^a˂(}}DOM+X~Iqx(N:޳8'{gC%ax~n{';ż-[GL`#c6mHlbY]r+?N>IK@҄F)B  g0}v h/VQU{4zw8u"/ՃMyB9 }č2| $`hݨX6y"Ҫ$D'}(ՋY)i|ga~4S:IZܞc>#ڍC9EcEj3 {ax!$[ gUR,ӯ}avmɝSD#ܲ]/߸|)'tg$1C G0fBsduyb!ҽ6!Hq*"Xl?LѢ&3u7PPPPKBDQTh~NuW@Ը<S`=y|a."n~,DY S?3U(n04~܂tTCröaqPI }ڀ%y3[yDUt] " 3!=Kߙ] , Õ:|[>oFuNNJM8Nڴ^u7Q H݅zfZs r10Njrg|]*y͕2(Zj")0,t8>`oT%!KaYxWO ,Sn8_.+G6+GAU$M6rg]bIu% X2=|4zK$/, jaXK.Hrq\!Ly\3Šx ')Նz5;aQ.5=:%|L+/ScUx6`gC^x(∣c^P 4?Kׄ8˱l{J V!O >li#o|C&׷Cx9< h$f v_?є"Ό6!*_%\[_z?J/kpOJu Q\ev0ݷg{a5OOwu[u>0햆0UL^O1.9e}Bەj{eM/Sv2m݈B V:<~\8Dw-RGV 8׳wvkn csĺN8̓מVD4a7Uzű{׊6 -ۊeQjE0i7Cf\@MLgH :PQ(B89 GMeϚh)؆>Uf˪#I ۩{ًY.0r0U声x6YzE6ƀ6tYQ9sM@:%mQe,z 1 SQށ$8,ZvY6RL"P2ߩ{qAD7;\,xE3S,43w+8) cjQ>ŎTTPGa y4wwy8xctHg}1Rށ'/6"vk YU2:MtJ3f#ot'aL\NqJ1:%ZV ?]6 L܅EW[KdYхZs )ip o} R_p-1gپSy_Š|Җ)}>̫ui|LC-\Kp: Z ` J?U.Zu5=/aC#:%*I5sGN:Ff FhQM1i&Ijͺ9!4?m2ܙ s2 gN^+\+>!T&qj)1M^ <*vWsb`~rۮ(6BUB?8'TzDʇuCCgj|Q]fAu*KO\$Mwa%-s*EK*ΪYVtPٳ)I3bqa;wƻ%+Z'Z1~@^8_fÎ'Fߗ^䬼LjdFb2Gh;YEhDUXKHf1>ZH0#^ƊЋW4F@@\s!ey_Cd嵢{!4$U[`b48M o['t~D3A8|?,c0v, 5B@}_=&_і:P,"OgýxM,8[. l(?l{n=l2]>ҏbwltcvDs M'_PA/n@m}e4:De_/O2=MRld>/z<+`KC )=SEZ!'7W}UkHQE\.,.|\z>N43=Ba<٬q PI~/CyL]Ybp:맫't$łˌwcwh).wueV@c|ÉxgB'r(or,c 'dX1i~?&9|ԞS"˃10%%u { KOKٖ%(R9[\RLHzԒp,Y V㈌QE캴8$+&NxmCFYsR _yBَ=S ?7 $˜/_62{ZգA(E;zjIkR2'=7AŊ\wT=g\Ic蓢#Ϟ2Sp`%%$MC5{D&wCR- '¯=i[5փK7wJc=\?1*Jn ߘ| Hb$Qd[XVJ͵rIEj-^M?ZL)F?;m}]~>p@y1H4 |׉RyPo!9L# WzeIzT*fOLeFqLц2"0^|\c 8$tЦ>3^o4Z{6険l].G^MDŽαCK0ZF Rlʍ}̤b<Ѱ#K|y/g4ToփJ}zMC2t97A0M Ć_E@q.[\MWLd9ro8 mn8B3ђ;ep`{ʤ{·) y]Ӛ¢uD = h/3467JOM'v\RuAEv9>j"h% )^FF.p_]\EwmI6`hǤ\lt1s~U)bV.O%-V|P-΄8:o^-r*0 2-exK^U#x1`nSQT> ִ,30ZT^M{tQæJGƳ&z]^ 6%7j}Z:I iU#Lie^I&(lZ*T* `׈p;N.)DŽ!Vg)#͆93*$p) f8;qN1 I[Id#-ᰠubq9١m_/dSwWF`gf5&1ƒ< 퇓,]PYi2 N<{/GDk̛XDH9?y"'=KR%HAXtHK(k*O y#w `F).h%I!+7_՛} 9B%{7%ֺ)h)*'GZ\ b#;@4KO';w I ?#(!$\ QAHa\+v17`=WL|](u7Ş iWLQy* ,:bF/̣O %r@/{E}uWV햐Xz鎺-$NA" 9WP/޳rtT16pc>t; 1pe uw Bn4!r6rJ4]Nj~ oнIp(Cۮ%b,L-lW! 2V9Oz)`mC߀~YSz aJ;Mx:cqUAW櫮co>)pTyafƉF]ϫȆXARos.r$ӷ*ԙtL D]@Vfޟ<`+#kZƽ x$Q~bW{N7ĀTFZt[Uկ[tR4ۍ?T*K3:L_UZwi-CNC FJ KvEDWϓed&D6N'_¶(5YBڶ@.l~B? f~4},jGtK9L3H~lZ*߯?ͱzf+Gm*Fd7 -ii1zj᧤?,9f~S0|H wͯKG5xHR,|i@-Bw6w Vv*㉕drs|OψLJmJ^Ym[YcZ?3$&I| wݫ= O Ī B+S;UݒIWP }FC I9q/Fbmޕۼ+JtuC7v-KNq|IJdr=il%`Z-*oo݆InӜu3h%WlPZ.+*!`m(Hbk4Õ!WQ!JzW6tXM q*\INXEjNP9rxZm`!lbZle>? Y C {:Le /靉ٴ@~h^[hlԸTk43cgz>g3O1u* v(`:abC5*]dJQ@;ars"­tgUO}hg<i;7:&ʔ eG[6#@NoC=M#C8ܦwkO3*V6 tC*Ǽ pRZ+sSITF T+t#'&iò( YTlLyj~4T 撊d0rk}ՐLKi0Z/%rR&$Z f[s kTvUnKn[GߌlQpTx&􇶦Ff}v~W)>'nVզ=ϼD&9^ ,V|f϶&fLv\,3`RP'A9= o~)ϰ^439[O1 c uenTlMd k|yN^QBɻ +8&bdM%`L{2X?EJ(ӕhO` JMAVѸ;@ܐ]C9%F DK{ :ed,U:r:TrݡG#Ɇ4S }`hn^MV]FgCӕ4em$FށR6Yy_h?ZbjzT!p&Qʱ:;,:;c=q,`ȗq{%ixl걓r'sČaܴJˤW{ʨ{)W}0 Rnˆ\gUuqMx|miD4أiB%&!AjU l5JbsH綒nw=|;T9YZk23&.JXK S'xy|[$+.ԉсX>w U G#t 35>ZȹP wy;նzc|7YGdo[4xR8O KL"mLeo8O562iS8YPŀ ìe+-ދ(gōH`]wdV:afbڠlA@fQ7ư0Y.O Y^ɒKoe>m՞33LQx/2څ^06aLG"Dq')YʖP;6˧үaGX;~᷂P4CUU]* > fҾYEZj.QQWj7utJX&| q` @am+g?cC,$羔ѰH]x,pFsn"B\E|BL&!A]tI2!_dv9+3uq2Mv tF2d>ϋ󷇎& 7u|λ~`)]{kR_֏ŭ׼rЩM높}`z;w,CUJg u".EM5]fGMvq̕CϖGOqm4oBsM[jI䑎8k>Ⱥc,u]wzl^k~rK7/TZT =|DH((B1R/2Qbz_\,[;Wri&$}ٞqV bT{joۙ] r GUOGxSW`(bTM=56m=PAZ53qL͟m齱~1e&ތq :'~PʿD>ͫYİ ӮPM[Si? >(Mn&nIb&Ϫ>_{J4L$WD/9.eFɈyl7S:OksV?%&q/VQ{EfQ<`/B, Wesν̓J9T-"oѿ "'ڤw6#ёjN.GҀJ6+`yt̔mcIǎ Sop舗qy*Җ> Zש#Kcm^F/YG >bIN ˇv8v߹P iXMpOlXIE43> 蕗ea,42YMQ3Amo`Dt9 i@W_\K_ML$<ԧER܆G)r 倃 F|D"rF ~#T dZޣT+p(3C |kBvGPιfD' D] \5<kvd 5COR}cUZ}҄M:B`ɵ߻ ꦖ8"ք| ~UxvTur(09{m@۱axݤ%4Osjn^]?fO8Es62(k9i.˜,/xu!31'm3z'<>IrTs^AxXr7iOH;n=V`N:Lg/!ɠ0xzAÄu0rjx߄D )jX_lj * =GRg}A|&rT9[ ̌QFᬒCzac'ʾ)65&C#ը2'`⛙,+kgx ߤu,cѸեN ƿVU I7B|߸„sj}JcoErӏFgy=LnT E ҉ bmA^b9ScǍVAK1ԩ6rL3b_<7'3QKsӸćC ".MyD&y V~b7XINL0lߔ5;NoO@NTXq:ViОK~I=@Znr.H$á[7*/]K~vK^{ĝ4j湱eCe"L"B[Ȩ2SD}Y n.t ?,J& (wB ݑ(gl!9zg=˵j GζR6u^3Å/$HɇirL\$Q|l^!pJ<d~CjTmHU4i]x-XmY脀A 2"8I\ Z;B +ߒХ֪%xo` WV).VC7$r:皱4mOa7VIUREPbj 5:x-N 'Q,*gn:,yY& ;o"@s-LIE6'Wj~ GjUҔKkm e$V]( ޿iE3byEp- Cw\0^K.vsf3 g! 0 8b/2ynY='6=a! m8ȝNRYXš2Umjq ?٥)!Ty V">PMh1WD gT~# iI6wi!RtʎB x}mS7<,'<}=*;LG@A0\UԜd\·;DW#pTeSo OH |ؿ{(,VrDA9 s/`9&Tsj5W"i⮃+TE۽('f*2}}M8ŰUwW! ڃrQ6nW/!;Gi+Vi# Ld{LApt3^Ct,nEGzY>v9hfmV6re;.iZ5SaZ5t; pF9?#Nh6-J&>[1tlQe*_]Q'a-eg' [ 6Q*PFXC HL3\=Oi8:$uyϿX69W1_J8GZW>֭VMJmA !w-[VJR3m-V2Q߿@Ne'`ةobOhU$*nX@k7F5jQ x9x?AowGkFO!`WrT`ym_ΒP*@Ǖ9nwԪRĘ4tWZ6qDjZbɋ_k4 7vo 8 v e׈7~F#c_:P mViׄͺ g<gǔڻN@AҺlԉ U ij% <^D >/A(?ZӡD%o4!! kʷ  zZ$|бTC,rYoVAV`P*'\ 2f=jj_y FWKbemMf?7mNmH^&Bw36Kk^6ZꕏX@ܳ$ ވ!ή۹ި^c' sFsEze(2)Y 4>.oX`ᚕM%Q $ҩކ(5OBiu_&hcŝY*f//ӛr//e{*ƒ+`XP@1JdYK4<ψ:"PFa$v,J T9aFP~39sf+pf̉:y S VAf2Th;qkts%,CjhbysvWȆs-E?MW+IꜻqSl!Ck ZS9aK9 ARh>˽`>V "UQi͹m9/X_ 2Rpy!O[K6irs~`DYVŒ~w|"^-z)MB\:jN$ Cܠoa ~<5"uwȲuxdUj-=lKly&\C2@T~\UxuERZ6}|tlr$tGNM#țFs2l_ 0+Yz>^ I^qB#y$+O}r /m>B?y'~F]1縯>g3^Yy' g/Fk/ waV;*V+c(VzĜQN=䊪\Aoɡ;p5V]na\(_2|qtAL WfBin*1,;rl.vc}Xp*3:Jmf-(qJɒk#pFڒj@Tpv(kqQ-{.vASS ­]Ov#'-uAUz𵋘"}vR^csVhk 0^[wSy$a|{]ɦ)i /{JA J ݞ/VBߨOu=e܆=Bjs4&q@8#,l ɍ(97DG=ЫLXhAxYEKמG2ֹeVy]N.#DK2f?!ъE>!Թpzy%fy fZ~ٙB8岍 Ğ{"G,R$d95l)GTAҭH~w]AIJqͽ9Z%F/Mon^G3dcǮuKvf"uIBc?x~T$/Y Bor(U74p*^A!e(&c O˧aeuAm4w6Ҝޥч<7% {PCzϦ׈jH-p.|59>*wKRЁG|K`S"Tﳴ<:J*KRHj]*'zG@C%!htyDHʟlI2hT64UIߵª2hLBEm_Xɕ[/16IrWP.ZD:IG3 ! h+ 2-i=.*.Q`V:ny7+?fHapY8s߃PwI;s%2yڽu[Geq|5fcv no WWz*܄7dQZF J#3|"b᧌x=jj?܆V]mXG=6qF2S+gă%-BJ_%6sf4@;&Ս מQ l-1l_v*3t/gM$ lh[ =^>3RC56zCtNYdם% ;F!0r`8kLM}ڕV} 7@%%lVYA-IdpG ϶ %1v3Űu6UGR㩷!?V8:f[`8 Ζ )L~)=c('JgCth=c.t?|]|Cm>g8ԴhA5俖͡ӓ^Io7>+Fx/Aqd<&ED Qn`? C. &BPp6o?TkkHol;N!ᘦ@)UNGOc~;.qNው$w;MZdxg(1Ӓ Ƅw;Y l.1 1 bb/n\<Ի<#;heHKP+lZq=T͚o x5y7wnxsp 2Ja&^I|fq9ڎ^RX4 u8YFuZ${ŗ\F7U jbэoyŁ] Ps#䇎ySh'8 ܿ~ 5ÀK7\F|CO nU>lMD5tҥ=چM2e֕_(횊%4(;ɽa;<(*}`T"q>FRߌh~.]0N! K:8kVϬ|9 )q6(m{hC0SQ& -N\ Ch&x_9[&7Pn %FkO>xoƻS% m7yc(C|v$[<2@+Hm x1=+i峓)0|u}jQFudEe#ddܛ<'rVlMЦ-Oz7ǂv n#=w+Lc!SZ|I|?ܿSյ7$mXuLjp9C[:/;n$Cz kӄ<Pyur37Ox7Imֵz9PNC0rGmW"*&sfI9F2|R']j $-!;܅˷%Qg[&-:`Pf/pb[l 3O c̻b,AKh໏b*<)!6*M*eGf^$L%Eޟ!^l<Ǚ=?K Lbǂ_a V-(t8?شN=pUzQB|W&m AMqXFW7xt[0l'hSб8VQH>AՇ^,BAze0vTecYPiO">ݑܝ됂rS2޵G[3\"&atZDCGkz@j` ؛RcWa$v&;i{/zS~xgPajp\RP|r)2vþfy|Dzq_=Un)o&+42JE*AN+G\UƗ TL'#$?[zeuKe1'1!І]o x\]dV"}VI?\R `&nYܣ.XvE s{H|tXjwltd<`hZ'Ud͚a'Ť9đG-2޿+;AWmZ}Pj|ācWF]> l3KNvX0v.B @s(BD9p' 7wÞp1־b3Dp*UdTJs1s,9wpe6'CA&+4 u>޼0m82\Tu+5)7ҼIj4E:=~Z 2'ar2m&ZXVh#C˕M >,&xa(p'). -A3^#]RiTTy>T 3&]yiXjv]C!P`&h, 2s lJ9X^R$p}CrV&Ւ8Xx^.Kv@0޼jbS|IИAxrT" l$q0؟=D>9uFG]2y!ɘh}n7hMUw,s3yGP.?km0$ Ԡ[)7`7|%X&-.quu9|OyށK#BpJ\lY -m3!O&,$YɃ7^z؊ 6twrIMXZ$ͽ@"΃sshxI,{3 gbck`"MyQ/'"އ~PJha>cs/?v|QidGLp [4T@^_eTP5cgeYRo!%#>! 8=쥔2Qx{7D\8:B [݅wS^+i/jL&t(&sP0i-rJPuDK%$aH܄8rZL,1@N `㺌1?jDÎA*&0rmIv!g^RT &_$"`/CP$3Vدnrxܢ7f*Q \k]Qgƅp2n㍍E bA}BUG]IrϠWS4]@ Uk WTX'<[2# wCM>Z6#Ҿwf[Y2/RN<#@l 06Ϝi\ÆMF}ǃ-v=@9۽Bn9*,{tWE[C +.a%[ث @3b@SۦeK}o?wL]WhyÕ[M/Jk; l~ D[ YEG&E\২66X"Zi`< ӔWp"."'\dpS[wcRcEr>3L60VR!+Jዄ`V^/  >n"ik4K ^ i|&y)8ï%eܼGD#}wP?݆瑏\ /E|p,vaWnNQ7:gVђlCi'V َ])\q,tv B7|-›G*kJO/C,Q&z FceӈN ؁1ߧ]Y2v*ԳƔc8_2͚Z$.qP;EdWYjW"ho)Kۨs=K,roh˔d SgSʻ\O[Tlם`'WRp4 )T͝zm'ځWE Ļ\uRq0Iyr+P&ûc 4)Nv䅣:0m6,h*24W]$#m $;vA?ԯ1 ·?իU xbwRd᭑k9UN8>0{T]a<ܰm!||0A|GFB$' ][[$ _6bSJ(I 8 `;鱹)(Z;*ЛchR/;GCx6?cܻcQ}7p#RgGj!pٝO*@ JނE*\\Cکa?~ M~FsAU ks\1UMR_UaSSz1V6zϪ~gDbj_FTho{z,̴Ȏ2= #Nb xEQNzӅ^ۜV6!Nm]ׇJ.o}b~ًVdbt\kƂW |!g-^F}/B}|XLaT'\܀I]#SflH)1"Ex8H"A&o>w#`ՓT>D=nȯ%u EPFE=N\){]@sD w:$GO_ca_9ь9xf煅)um_7ѧ՛$7;6q FAr5G:h yVFK#gZ*Mu^v|#bp/\muN^\-T!e<ྼ(&CWr00pJCDT`n5𩰴m"8)zD)*QL{w½_a vJN!b.[ϼp9 HnwѫhAVw;DcZYք&z SL^N^vvfbé6{"w:($EaEliތ0Mtuy*d{YÒR FV:7|8qqo԰xJ!)fI%qC<)f ͒ըMRis0 i\y| vcgZeW)$Vs\=j㛼\.4.=ю-*" GRnc*O|6ZB: 2΂+~1n\ $v ~kg 6v0}rIEߞ(aRAƈa5(P))x%:VvaGTAyjhLm(B)Q~9Zs+:5QMN~,kQ#.WҴ^5opћRtxDq`j 0Of]J#ʰ]QR\%}olCI*;EꦞwݗU ֹ\¾z+E pUԊL.a|Dl l EH@}Cyң<J(n*\Flӡ6 -Pij2h59~'Ce}AJf>.^*~8 iXZГ|ԤH` ÄH0Jడ+a|7!CUO&يTNL):+u)#RW.䑕GA*-Ucʭ73^=S.WI"#5~85Ke,gDK 6;P .';10+!$NdԴ-j1`>兊qMC8zdQ"9a/v|EPsbBE>}7b-ԣ,!R97O^[)ʄޒ`%'}HU'Z I|tb[bh9:#d?8UTk:0nsQ W,v+-8Z*$GpbM C4\N XgT|[ufvr%$WzQ)E*:D[_d6(L?3l 9)>:P !:#S7\@@4,;e?%pRVf2wmjVt)ra7Qh8;gi؛ooe#HҚx^@1N^ArH(a~A /kzK*:*0K:!!2UX5!k Wʙ@/Wy mQ.5H x/hNLND&R   xVkA.uRY߸~ Z5/A5 AA'AXĩQط.$Qe㱑w,9 ^bɍj}~uy"Ti<;h*ދ5Wmf`ZҖtׄ ;ڿpSUMlZpf ‡g3SJ}6ٶ U5N(CĒ[IT.`ӽQP>-pQgՉnj=VUj'gOiwTk$at{-BYr鳯0L 'ujـVah_;}M=o j6 [Gtb^wS"H`都ZP$ODeI lTd@3 ]N+Yy[XSRq[d{jZ&z_sbL׈hC!$W\uK9P%< H7#C9Τz}h{lu,e/@9FoUpґ;v&tS[`qN*J )"ش-)Khzm5GwlJRVWJ E2OIZY_AzoPdK7Z<4S#Ͻir6j@ t'SR ?:{kWOU2]ZHآ1'q@6T+5f@ؚF1/8%XG/j:cgIQ=FZ7ޜ5z\v`d|x*(pJ )rx!{/o=t?k( rgxuVAH4})RS8 .R6l5ǀ&*)?+qaC<ҿWviy?-u!177d5 tiݝ{410/{겦ņ_H&md؊^!_g䐝:j-Ld'GhD3QuK؋kv1$K"ѧj)-O2Ç;-ޛnݠنE=8Qd8Jde FͱZO=9iy ]6˕WA왠AkoMhCTD9Rʗ2׊ ‡D¿0!Oϖw_Gwi~oE{v *oTi`ԃe}W̍PIMyqR!sa^-eU* lsr F(-m`tB\*iQ~je㖠dZ!m!%=THf](Gy}B$-Gߦt: #)0`6BfP.-@U͐b_\/""[r D>Zcj$EX p&CEqFE4e!&a/N|Asma nq2!@nnj'#?rG}4;{(!GFptҴ*ܾ-𯊪v;(6؃@{~&1ͅ{qr+I n.xv+r(̫kKT J+ ~1ʨ|EV1v G`W:屆F=d }dq,jEvuhm"4~(UPA?7ת6=eJyms-ս> rUۧa…nݰ]nz.f2F5oKˮȯdA>7UjKfJ-xd1@߼@-hhf P L}Z8F1?ash|F_xN$FM^ =w.(݇  BZeQ·^z90m?ũW紋3W~_*jю[ZlJur}*@T5*k/~d5Zh$\#.YGvPbbf w&21nOcڹ嗉= k5:aQxQ_6W@9.,r}Kq゚ 2U]Pд,r!J8C=W'Xzegu1 H&b֜4\J q9J XgsX}t(FhIE+7;g|jW%IAjQo$zֽJn]XW,-cEIhY_9r,ˑX\B}&Apbҭ\ѕ]S)jπӵ<)@/\s1M]V$yk0@yS]W#yV-+ZGw Hr K1+ch V8aW3L{ݟM"eוڡ1~scZBVJH U{v4oHn!ۄh/ӥtj9 `WskN+8= yB̢hN;HQ) AװC쁻ݗRcwW:êM_ "ᆝؒLLuJIJSa#T|gksIFRQ5 qu|,+cpJC|YgUXmjVG6顶Ǵ|샦Ucg "$Me߉ 9RK-j-9̾{-?q  Dau͇V@lY9>,1kC)eƁsv]{Fz\ YZ*=&| ~EWHkYh_mlbLFU0Fj~筻/^b=\*SfСTOf#,hS]e%_6R[{ӑx^2#hsWk>$uiDڜXYU,yLѐ,jq"X1窒< U-vgYV2сߑiɑ{W&3ɹj=>N|$mK1S(d7:xhLǟeX~DrYys~1i-= q1! GPX9Ob~xM#ȊtC;]4ng)x#«q=0zP =Z FlT3̢L/"nZ>Cr;'% Ժ/EZA(%GP fpK6#RąM{'kF4Pp A5Y_U IYq9xVh_JEv ~eAD|kdP%>/| 4T!=\=|5ԫg3?=# \cّt'[蔍YUƆW|Z5Z&NnҒ~RŠkI C9v0f1 U $%7ֵ?F qS4MaMyT֎C Q 0LmX6+- {F'.I$׼(2FHW ~яzP+45{iʕxe7̤L_-;dx;%r+.!5Kā8 0t m=AK?5nh#e1ۡ?h.\gq*~\7SlY[[V  .zV!mb5LiMc2 ow}0*Sڕ 6 ۿBTrNb2u;\C4 ;׸1;߫ұդ,ؐ/:#F{m[2vX g~jyp(^iϠZGp>_lfri:286m*z_o}濫V.D/s 1rXǀ϶0PP#ue:e\L MfxQg &zxij@K<,lFoy  5܎PW35uMu O弤~i|GX=_7F2mqz6 @ ȓ;$;fͫGXC\6uw\} `P.ǘ9c3`^IS(Ki872 9#J2S]v|1林{J/}LpHT%K9}2bfK 1:$bMuJ@gf@=rٕNsʅ^]׹ڑI팴{afH.xkCT@'])+ 96j 5蔉 R0twXmVjᾘ_)iG&NjVv) QkL]󟺲,8me|wߞ"5cRр0.t_Rg+qčF-!cj޴+dpgC l!2*м[WRWr/"vSGN`3zcںg+? "ϟKZ촲`3ֵM8Z&e΄W\b(@kp} =5hk', Ȳ]kDӓۃm\h$V@"G#d'Y$C5B;'9uvwGV[GuFfNۤC0(f qu݁_P,о_`-%l{ʭ@hPp3 jƼLȦp -((Nm1qcrYgSլbe+Φ5I;oĀ)ڀBzF2ӘR"z(ہ͍8ÜZ")s? i^FX)/;NX$b%N` #΂Q-> K˓ojՁf51otƣ93#R6*LoTp=<@ /;#71ݓ2M+qifd96Ǯg"UR^bxuZ7ĬF5WUnDM4*1Nѕ2)n[gm>gKsj?w (kLq,JR. e 2ŀN>5+qZ*j!950|K!6t_[dk6(l4MlE!o+dP$'fȣEp\|>d/(8;{ߍ#\2GvUhՀ[ {oY=fqXGJ]5!CPts#\0Il鑗#R? 57ž`)X:a"xM']U}j=}rjr:ZxKG@߀r= pF&z5IiXc*+G:#r1շ #`'j}A}| 9 5$vQgg$}Dy ;LDcs2zږV7r5%"H>*D4O](ʀr(ԢD֧R뷯'G>,rZN:8gi*;Zd3wІJU#Ż,L0c#s#ғjjbّpjlW&h>ͻ/`hl3nu#2si(}$܆F7Fo$^\(R=U9槞1/1|_9 ?൴LȖ ]@wZd K .^=QY m1jΙλkRY Ula*l:~$UZVSOZׄ!&7 cW I`V/hA._[Rq/Aj]W`sE+!m@\nj>~5'I1s1Im0/+/$uryh*Kâao< MU G˓-o@,k{زq`*q4@#=9VÊ']Oފd :frUUz{Zu˴yjWVc_6`rap8I u=s_' Ppa#pjp7Ml;'-𥘧[LKNSvYz, .ǐy/&eVGDæm\TnP ,+ 7%vuӌx5ChY_S^ي`driZf5޺X/1bs'! 2MS^;M?Y+1{5DE3rQwʦRZ+.DZP 6+e],aԙ=D&_6l@!u;CwRtT:u7~e_~JN%UUMZ4|hjگ_߃9 Hb|3.˝ <Jg_ӄ;rPI+hW siogM :Hk''%gkU$4;aL;`0;r}3.lt|Kn?5/qóB;5 %ÀNç5,#+[|;8Zz sYiY(#^"ThdM^bo%9M;;eN+uhnH3 ^Vt6ӮwC"Pkxu}yȦZ3ձD !C Kj؀J_^;e Xr<`r: k%JP',R }6KIZGB#?Vynْh%G)gO9A!]5\MHYq>d ;GG7G< o輸5:[ ]؋O7t ku&Y0l{e)fbF,ݲ6-rDt`fwѫrI1ZޘU4|_0vjюDd>{ZA6^}rPD8eHqɂsʡu=>A:}KM@lqF;"@AטxI߂u<ڧfj|C[PqƏx9ZjFLj0Qj uDZo(Y&pK#IwW.a5h~@l")ZYKU6Ɲ_+U(8J'vC[$E Ph!-\Cxﲍt!ujh)g\=rvOizx?N+-xY-^gtBFգbJWVO?B A;9$w2(-Ĺzbq &hNG 7 , Q^Kɳ6r4 x!Ӌ|.nX7,/%bScҋnmOxHmۇhl锛5t̮@+ek  :`qVeSGUU7fQ5V_/%YC6VAnpIG`=.xZ..eL624R!lDw?Oo< Shђ}/#4yH;`0[>,+=A97ͭ/( u_|Wԥ=P ̻?,ǜyYIm6m&AQ'X.*y`})]S oerexrYPyw.DvԤWɻWYs):r:Q#ku% lOЭ-I~PQ )~Nɥ^MNyA8'C@tQ[_R4aq\:Ua.(fh.VfoaH'9Wd3*yy+8H)ӫh1z`$ WZ YhBi8{F -jc>6 øBL|[)Q:W)q͍kĖcjdKcHw'◑]Pnm@d^083͏Nd )kFkNђDar?g%t p`j,}aҊXWul}?G7|WO;pɬKIɝcŖ=iُc3ܣVM&Py?\hU$9A{[Ǵ{CsIL]=(7]>xRDL~3%FB YTS'QCЖPjVpԲLkLuv&3#<=gD$Y ;F6)=fMDfE܊d*Z Nn,7H:u af1|.PfQ&5,f.ƶ"˪ՒV{7B38es('%jwO]ބ]yӢjBCn:c2qr&K\> =ʐ  _HBTBOoV&UUzm'! 05|'HE*in-QT|mh q%\%L͞|k@\J龲0;ITe(eȪ:x~c{wQXw(Jض") =gzBb +*ڒB 5dn@Wʒ9ojXփhm=K MGIq: >g[Y%t#%-RGdko8u&1Λ9 r F]į~ D0&1~Ma%X\hrjx~^9J0o=+::.kF$ )G?K0[+UyHeRNX̂b#V)i-B@8E By6\.=`G/j`# mOեl +mhT!+TPe LgADG}^/RIWgW|^'o]9x #15;H/k[h hJIu.KdAY?RL%*Ox(mwq"YQp8bUʶ*±@{KV9Ǔ?SaAB1Kv˒UM!( GTl/)e0wU0'b II\3.QY q: r[ +){ -1e}X^kz@S,EH5P'VX߽$\ɓW&N)Qfdz/lRMmY-So PQmTXL2m,oJLO5:1iԍ*+-؎- :en}?`loB@-_d bʥz4H/:؎ Zl *{CQR$MgjK[l?l?ƹ;!.MP ĭ[lc1 b,T ,;P/Wfp/|b-lKBAf*mLy@o*!6 ځr.VI/#}{qQѺ*B0 gW4F X$ j{v8|a8=چ6;4 B 3|T bU\cgm$˫t#SijPD,5W^jޘRkCR~xҜ$xwvOX3`zp,>(3 A@Z,-fo:,_e'azguY*kf1I7I7nɯL-ayJj{}q > WsB;:6=<*?*#!Lojv^k_&xCv(ĮKki>Ր(ע# ch>Y+IENf`M^"ـ2߽)Ԗbe #@C1f0iVAW]gZ(;,eU'Nw:(@UݾÈE" aE_R07rd(*KUW[B9c][CٙX9A\D '!F8-b26ң\' = M i 7{:,pu^؇S S”FeÀGHPiTryFqk;g (D&9)[1io걫?މ0n5dEhEE״$]ڠ>;u?wf@H|QSG6z@_}@ܼ 줇˙Bܠ`AޥRߖ b ̓,G hZHjEg]}DM%Q\LQ@ĂsiN;BrD cJZfo@AlMǦ}Ex[y:5kYMR]/,؟H|l̝Hp3RGKvZE 7)n+,ongAw(:L n*'.*%,7!kd8‘C􉂸f')KΘ?^1H؊,}4Xc 2L=2x`AA0cz? VC*]*d.K?=tQe`Яk nT1iR)&Y}n ҕI[!lc罦>D C0E, N?'$w;}lt4=΃6ʼ.c;ŵ 6}'e+ydJt>{d(ԞsYf܅ 5NzrCVa UlB>%McڌUqSu;,:ƿ'-gG+ ڭ)Poh"V{yRfI] .*#4KqT:.ڠ͔c @#ըG[1f6a-AX!-R%W#$mLK<+%HFK+n~YRbBd-3_o}` .}e [tLнk DŽҵj83m]@fbrU^◷17ǣnܞ79y0/KjußC4lUN^{vh m;iް"8XCXE谿ufQu`n:|ɽ;dr\"Cuwꡰ 2Oސ@yP3CkEZH?[-10ı27DZdgץNq4UC:܃crͱ ͩ2&vw6pE@6wf+]WFV (qoloytF_aP頹!~s偐W墦" Xu~{ت\ߵn](,4`1֓{630l/@3( .m3Xӡ͈*f{% Gt "vw"}C_-$1!@::ԑ>^t-p : )-fAt"ͤry|s Z$=ޡ:LGֈ<,OG懮p75hN)yZX(oNJ98--vYFv:sUa u}s" S0Svq?128^z8T1~Cp솳j KUG%ʌwS䏤sh2'^y%c~P&=weY'r66s(0q`+|M1k9dKl#ޟD7]wH|32("FTH.x2ngAml\a5/&H{:}fk5LE[~ LR޸v\zin&=W lkh(Vy4G+ 6sgρ:ӚzAu:Qr4lfV'/%4k'7bؔԨ]p΋PHMklhG 6oQRSF ?[鍾e9MG,Xx@l{Mj_p'm+"]l-+5⯀d* mJ3[kVW(ńƔkrb/ Q!ݨ 4ܡ q oD)\XK yȮռаuAhYI 86bM _c;_Nta60pJ9?2{:fzPjkFA͖J)rL(id–*;FP; aߨD/ O:︈<Ұf LX^=xry%> <s„,gF#~jj[hgb2uȁVY4+_8%a*2s(Cu``M=-ˉhO;1(5,̃?lw[$ <4>UWe٠NVW^0N6i,Al 59Vk ”GmGxH˵!Z!؅?urۀ%4.z<'d}3Z`:ШLϭ}Vi U%zdRƑGx^ND/kΟYy*5HΓښ%No$9ġZrd'pPU.ai61L%s^Jhz]r[Fvڃp-K c6Z$ݞJJ3PO.X{tHn3lquKiNj ͢LdU\؅@g٬@~.Bq| Qc)A/hmWE%I qѱߎMoQI] T]}۟)(fQPcjRIx'9=5b Ã+wuuG>"'V:ЧY5ę7zKCB-͔Q[ =V a'l8aGn禛EtEH}QvHgm=!c|j hѕw?wv}PyJzLbQ7s%-wQƌx^Rp;hc[&>)V9HclF槄M8? dṫD _N̑An-1 svaXZWYE"S{q}0LS1Ս}0>]YϧЖ;sšဂNBh́A|y%/azuz Ϡ^ql@X(r.97@XƏ`M6$۫+R0"q>*VgxnruA/McS/$W\}YY%otdƁ).'`b+za ?s9C%nX%;g'o>=#B-qWsFd-ao煒֑oHGN}9 ON/kw!CBRh\ ~ W,K*9Y D#@Y(&tu*atn fr#ph$Dģ[׎: rR@  D߼HCyiDe)wy&ʹ99m=FAh[ۮ9I8?sx- حyD6~e(<@A"@6ia0=`ٻQ9'`33P  jl7jAxàkvqd} b3'*Z})YCZCWI8O, ݖ88O'K[qc6JKSjkWJJ,dPCZLUާQ }lj7]; AxMNETJI7Ol?OELUj)'Zt7M94 `J ~"$d:\bFdZ`\C{gsaDϻ͑3j̖GWOf#{sIzl #أ=tY ?|8-B>f9ogDT5/$꼦oֺph]F%:~@\.Ǿр$"N[_&TKoꡣ-'IM`fyџq ifZq9ta-xhzJ?51B56$ J軑V5d-.q*7VMh8a8u8M`&ջ! %D(y҈;?K!܊w2_SNɊ2)}pm+3Kb86cZ*1Ɋ*VgZl]tώ~fYzEVp;!h k'?o `X|VLJ<ɰ?~wڗ7K=8 q(рO#U@'#yH!nX[^-)LBM Nw=X7:GhGJ58xz#,kғh#F&{E2LiuFN¼4P@i 8upk({Y˳]QfF1I ;!j4m. ӓ뽴yE8SDU$ƨ$>8ׅҞ2H}x8=̚FvF76h C7!sGd]S&v&2x1Y3 -Tv?ca2MwU3WzgޕX 6 ۘZº BtM|{NdwdN&ƊS?F\9ն3ZLjSq08iN xo[`h| :K=S ;<p!4~6L 6I `@*z!=P{C(%v^_(Dm~E-%cO/OTn8gXOWREٮ Bv$al'VY#JG@FY?Z& 5V5; ʁab H6n/y Q)`gRzkO&FzlYK:(ci5H5S6KNŧKIBef+;w 1= X-6(n.E)b!ι^J" w 'gggT_WG *'ѴFLkr5&u4rO9`I"<0I?+kARslBb J/<"_mr^c Xނl o hvLep fJq^(f;YV NED/1@Ǩ1[I AHrW^cYqL(&ԧ{4 |ܔ&G=]LB+,0\ޅt| {4e޲ \% pPw3g4Z*^=Sk(LJM},ֈpٞ$K,1qHݤXdiG5Wa8 $EX1ڵDqVe:O!űqDj\}Arv)yGoȁf&׺7^dz-¤L7 |q~3bBXpxUv5ZB8+ex~<ۖVry^s%A:h~9P#84=%Oo\3)u1m#-mX:'h' J>9>6Zμ,o'd/=¶>pm'3[LE;p*&lI5̑kPxwME`X̑-jë\@̙5J8 /Dؤ*Wf#M1`ܠs cQkGRU kM1;xER o= SZNo4cN7EK l $B"ê:vrhфCJ.aL%5?1#;$l9DTW]$+ V*~3zcx07Zk?zM2z'Xd?ΐ, kd]6tƎұGN^HD'@dsfozټְcyO6&)ʽ *#X2E$xIMW{5dW9xHSzyD VfKh84+]ܿ ZSlیp_kߞDF7aHICG!0eY7_H^̜2bd!814庈.)a*&Ԏꌀ"SDy]/l[_nO_wvW_h1I H?S|$0@QSnj[[a&B!=ӒmMRqw ;:CuHSe ϶7Zʹ힨![^7B /4l51kOf€@( OSN>)mpJ%L',Z52Y`l@$QWSYzyh?oB} 6C/3.c=;2w^\ oCukHHF'PflmEn {SAڽ\=OWo~GP.-MVs?[\1f8KH: nK+ (ڨh5N"~촻J?DGT9vgL8HlS;[&.0Qfܑ,>Wi7S1Bv0MX# S{B qer{*4M܉}Uc&jƈ q9mXnN7nrڳLciA*iO &z&=0PAڕܓyi!C"& FJ`wAal5*~w\D pp~N`sg WU2VoQ=|@\8J C/q=ܿVJo Ӑ) l|tǮ.x?sg:%#[R6< s69ʦ$N=z4pI+n$e`67ԸVs/W^^Nt꩓ =c8K33YLJ}t3/*u]-,' aa#iAK& i3%]A:ߢǼ]n9 t-2tbpa#˃g!^eNWjT~N0p\v}SeLL#=/T.kN|;1 DW3yoNOyV %rsK2 l;) 0k!vTxaJV ƃَI f$3ci+U-dHCҘ2CAx k%M'^ODoGeh=,x_|6Var|VeႴD~"d$/gӏ])/\c'JҠe'/X3z6MFF^r^V_2/5?G{~~e52;J2~ϛTmٍ秇+5NJCBWT\CsY'\< ?dj@Ĥh7'aqlϳF@O+R\%;vI),qon\wpZf4UYVA+WGIpEi׽~L];Nf7a).kȑfEb䘤bμbCA6&9k4ЧR=IK#j*1J |E f8շP u%>@%fWR[ w-".}ڦ XP+:DPduel-bAn٤髣GA_JU]tšL#C0yHF,:`> ҤN-ay7Ҹ!U IztJAnNYGew㑾ܓVx/chxY 5'P\ ,0|T)2`Ɇ9 yK"1{*mZCY9ïolhC !Oϰr*|V~ϡ(je-t[jw!f@8a9zӂA'| !— 6xAYQwuυIM4JH{nX;hK:6,q=R>j00j-]ic{ J%1鎺 gaP]BIGs{+Fn\ÐLwlhk[6?&e5257I) ȭg ~~(ۣ]\ť.Ejq*}qנqv 遰]\9Z)_..!DSvLDOڐL Ar.{m&:j%s[_: ? "i V" ]v`3u]^ôIwDT͎Ui]~Z@6 XM )O)d7R ҩxJeA,IK:\zjeLO6݂~/&~-Ȅ `GhCF~\X0I21Rt;zgCDOG©xϻŅNܿTnxU4eR_"w Jhn\!`U:ll,BH GT$@}/\65d9y]]&57G;=7e62nt) E qoD:9]7k!\ ,KULg$ y `"*Ғ ew<+HT0=1&G4a4a3ԷWI#M7W5DeU~ڋy\6|=;\C/mqoGz'+)+ᇂg)#8"f~QT'7&E歾^=Џ6潕*Uao #48Kp]= j լF)mߠ 3i]q%/2DਂvnsZ*{jؽ`EWB=wb:*[.jGSUTk>;,?b5 ơr3>nvJe.䠴2bW*>z\&%MREc]VJ&/Ү5f@!(aaGsJ@nkH6ɽ[&jN ztLeD&HT&ty:NSI!x {\LaWzN=Q|hz 5C76]`9 a-&ZڸaOtj¢? /W!+'DHXvI5^B/;x@>51Dsm)P/Lrm:|CE@MY]HT(HɫtmWؖ{_{|H$-pcVIL3$An,?Gc5= [ Y}0oC[> NGQuwԉԃdezQrda?I.9Oܓ90>뮃3oyi%&1?1{;$]_WJ TAkr<%8Y12}9أm*RS-gllP0j !I_Um -!AMA \ux/ t9 {J穁t/3QK>lxp«fzFzhF p]5γGfBb(ܷ暔QXZĞXVg@e[8qrU=ZC hEz:C#09OD|"B'؀h򇊎vn 6v&'LE <$Aj7-X7oL0^;]csnHs; tm<-7كZvE QK>"EOYqT$Hz"e;_mJ 25{K pb{X֓necP6P|u'/AqрsH& ޣqɜԚZmDq:g(nxe#5/zB[/ŋ1xFiu+ ='.σXs`t껛LEs{~nރfVogȝh&)5=$hHC4*L@ׯwOРd Cm77$#<thEΑ1E'~:*&u.s[[؉3`IbLf=ߝ)\ ;DmD.YR2J%.aoҝfKdyX'2T-up;6Hآba1FM!j(2)=TI_#{=%vw)V_(4#1A,}+2劆Z|_jGDX0rr>dlx">9skj7BhZ1//ܐV4Z-sgw_];#=-\FWlLpS$P ` PRhEYnۑ^n<{(+U1>8+3-UU@FXd*$w%ڄ% % ;wӡ_FQ}HQ[Z;nw^h' m|=%|c!:W䌱.zzr>uBW[AQ!EB&ڬ EhA6C&ޘbsjԊ!SD&^M7rdl7L<8r)oMm!]xЄF_fWɈaMwP"GAxvz$k|[$HLB%(]-jAM66%57,<(O7Fyz32Q+a4K_, \_v*"l "6ό~ԅ#޼'m=gKl8&jaNɨ> YO`ż àL SK~8jrJkGYY7龻2d@EP4'I>M Z~YgC<ƴLP׵i"rMx΅&]#v 5~ʁݎ3/`7_(ܻްc$ߗ$ ;MaEfў]Y_,݄9?N{&SLߝsR!زGU.-AD 3#ӓ<>`O rl jP͎ &eDŽoKy,27'8)Ԛ)x0SU$"LY$m| C=5E sO(*Dlڸ lMIb+d? @KWDC&=G'P ;N$J%^ZcPM2-N܆Gъ]/j36b0t7+4 Ko-kR`ϲɇs03:C6_yziդ`\ .ޣ _~J/~tt!@ſ7sm;O݉;nϡS(.diƋOxJFXNdMi YF>5U/"T-2 #QbPc5Ius|v~pZyr8!e/UTyg0I2,M۱?M#v` Ob( ^}?aȴCFu|> !Gq4SLZԓ@|50an 0ew=4K0Y)j^f=o|a-:`T{y%wUىB>':/Uh:K68K-L6iPOq^'t*3cmڋqdپ2[8cCMW/U$j(u!mNkNhA#o 3" cx8he9cNXϴZa86 h ã|0AV6.K筱Y< Z 7\ڤRC+"$*Qߩ|s摫W`L sqEyeTɎD}{拌zj`sʠHEw !8DfzMؿ݉w=%E&u~_c/fq Y7C+9?b2^@lF`%_(V!oE疻=!s+xxzǫN' -rL&6bvёۇpȺp1sKCB wi'Gu4Aqu#3&,bߵG9k e؆Q%!&7X Wqñuy Z["Qʳ g9~ MI<i4deW*;NK,6z(qN\jron}LS%x~$W݅~ :,bRTJ1$&1,(_rP@wW5KTW.,iѮ 1Px^M9%Djg UbiE# %e`N"y.0z>Ì\`, ߞ;OT:317Qjj RoƠ |C%%uɯ]B.dS;B <&ǦœB+ב{ H,j&5sR=3BͷIfu8v `Jso7:,Yb+ .=^M ]Ȝ;%wjFIwo?oh6H^Ap~ky (OsV6ʹk1*rj}kYӏJ?]HW1,l٧ޠ6TmS`5qK L] b'JaZ7=;Z!6\ucyȪܨ ECަbHC@?\3]#,*a/H{WJy 5۲^2Dj_,}RZQC2ʮl:wK\i4\riv5ɶX,qva> +_W4aЮ&1HJ˅9bCyD9"޾gsŠMLoriE* 9t-Ђ٦Zf<E 7?gwS!"VgCQmJJ&QLiShIAl"Ȁu=)Kt>ѹ0hƨE#.8H.9&ZݛS\a7н!y;_3˝3cm}[k^fgog-ӯN X k%EY \3+g,珞4B{r_6њ-ʍM[^#`ETY/O9փ V}i ʮ9\4w޻H!8tLGJO@LޠM8o~ؖeNhtt멫Zg]ϝ b-#JQTpDoScI&mKOܯiz!Nf3ů˝ h UGs pW__.c);_rxs[",N~6^R 7Gep8F Ui2ևx$ũ(k`Leӫ o"m|=SQ:|8Om>:oX| PĎoWV+OAYψ㹀䶯rwرaQ\Z{¹ BN&&ޅ,'* ƺ'w[" Z]nXI3;b igiLcebާ;/%EU8E:dVQ퉱=6wuFeu>qy yj)HÛxNgQca&g9'g^<>̆FC#΀R72?PnˑGÃ&zrMl*{V$ʝ-Ӫi/M$bq#ԁ jmS_Z;Ԙ4HpJˆ8؅Ԅ$w}N^w /T j"yZ5cN;· ](W^(B NALf{7?'CUCmC1qE'JD<]ă!ch8rRM<q6]\]jv>N"ոG4JT(O%Np7fN[q\#)v~VY5o6$ k앥P(Q4>ІpGDy/)YtSEmcL=Qbt|k_OA *dybʄ5,\is ry*%ϱA}~*=rjS$ 7JaݶVuju=`/kKx'#LBrI2A17`r w 7c*!}!ټ63@Qj8h>`rjɷ_e&|5=`jF]o՚x!n:\YtYӬh#GulY+*#O>T. ˚فgS x5ɤϩ.0=eaUŬO9I1^KB9D򶆆3tPu\. If֟?çjFn2gRrjr+>㚬$!kIlk]P C!I9ӚxՑ8!ݍL|Ãׄ( ӛ-?NawXi?ZG,3KqǨ|TTԔXiYj87B2݊p֥7QO~Z ;_p:6B ł\:YH{ RJc'WӴ)F`QkM9f1 ^ W=o"  S HM i2b>zuJTCh%e>[=^3f1 /vŇ40^E`c@pN#^[i9m7"|#on;&hHZ1+08^A)jFs-<vZ(J^F)mxd$e] &uAw"$XY.laYFzˠ uΒu(78T4Evu9F@vaK#j Bu-% a3d:Rzom2vA*p = %h-şzt0&~Mk#ZZҴa,kJ@HD氧R4ڻt c!g!uTA3V3<<ɧB:vhPM[Fzm#A-@ xSt+t,_77 H݂Sa_>]K'wI5m @יqQ\ѽ!5 SV w~O͖|]j͊*8=(=FZ[Eyܣ\FÈ^݃cEը}ՏYIknw-`Yb7ɗ%OvIrOF.eF/ZMv  i7i"2߈qA("KI*ublsYrF H>i"L1{ z0Z Sg->ں9o/uK'cqG/ϻZ:5$(E&,XiKp [O0vHQWLc?S(GrImL9ij,CxK#feCvEd(KVGr6"J9mr4pRǥti*Yyi0^+Ly4d&98zQ(BDZ \(wA odV^0gE{վFŸ 9g5a(2sԷyݖ&*%$2WUE*\(PR[pV ?vI,W>7gů5jGutv0DiMбь>͎4I1O} jowhCu)eآK3yrnq<ǪEp #QïM5.y:N@IX ִze )tܺ4vTD_ʀq]6Mp}Ovϸ4)71IYgމ))n fN?W˾@"qɲ'O +"pEAzZ&T7B˽rEAjq O% 4ܦjB. ;]kBpNJa"q 4͌e~ LA\5"Wwj݉b`BGzBc}6?T8fCF`*}蚝ϴq$-Wl2&͋xߦ1e5NEp6mЗ xݝPcvN{Rvnv~DG MB(b.0or-F'TCeKmn?b?4۬Pz4Y]=uUlYRTj[s{(NX'E'uJA|jml+`R'(t4RH~YvW8E6vJ25<' ೵3:! p:TR%9pזQJ:zpFmr\] bp݀F.P+b SAH>1^Ly<4>g[+W$7ZOO}Nׂ‘~Hp4T]*ꈧ9FNYBl΋d‵)!i2LUzrjm2m҈L]W= .J. &.c#a{T4} @w篯l)WW;-?=Vk ƚGHZ&UiBss2ո" Gj`?"RTJDCq *l£i6> 9 l;(,|/8^!umH:/Q IG fқlS = F%at6F ow &#'ňt ]vv1N Ecm\TA*ofƑ~#Ҧ`SaCHd`lix͐,Ŷ;WP&P &?X@|uӠ_yŶ #5e+*4Q(u?jڅ)6ck{dBX"˧?Uu冩TI?_dCU_n\csEa2k"lMt q{rdq8K C+%@7O.1ʽi>fٿ?10q!Prԙ F" %~Tq',A:y|du0ğXĐvY`ngevk~  qAFٮ~ێ(E齻}Gj|@ mz2 9K>jQoBf-9Dˀaa`)~L BB]cg,[ -;a.<>טгNEv]4x1NK ,Wb+O~ =:GHYP:A!܎.8 j"@n|o@`.JlOT65*MH [23=lQ+)_τX&y=q"&gM) %7 wvA=!kYIr]q{"#ٶ> ]@0<\y(UEO$z̖k 8m8i}pNn\ATKjnLs AbSp:ƨN|3drh D*5~P KϛFNkq#fjyW 7ޱxx!xD6Dȧa{c6*Ru}Mr( U;M8a<"IZuk r88gyhgDz14o ,~*:- iAgh𽰻KϜ036?neKKU w9[u)u: nRaLHwىhs-.<GT(\5'/x$^ 2-n!*0F5yJ`Ut~2]u1on`v C*A.;Mt -1Zw-ՑhZcqe}|϶]Zz]0©,ęgA>w^DedM`uz+$}^1QғTc!2܋pQTXzТ*V<:kEIF4h,[WApGYlׇ@͖aXYn"et2>(QŰ ҷ$> #6*c;{s.f:1 "{BF7فpl4 %Ra;sdאY:V;H'->B$e`16x׋uc/m7?\˥c!FNp[QD7naZf"߳ͳc/!1!cx&hɂfn.J5D czW–mamVE' wq2+wC[VSV#M "=S9wļopSyH<&GV Q}ς@o椤U0%C@i4~Vgzdr`/yۖ00VJͳJf誫6zaaFvԅZ{$|HvuPUP L-i!-dѥ *oq4cz#n\̓%lq)RYbvvh`I;ɕo؇\V^=agȽ0~B7afE:FG+э{RVBB-x9zޕߜz]*S{ڛ&96fd/pJ緈nV=6g/_BT3{5 } \ܩ{a*֛$ƵDzцT|.+ٻkY>Tc@2l <0UnWɆnUn#oTKTF@^Pf6Qjd1޽gh1T5Az2npSuBq`1ͩL[: l:hXu|OXUĦux';/5tI"+\&FaM`\3l a4Ae=1Ҝs%BT(R 4c$B0,czC}[h򰽺oCDcGO NQ1n[p]SDYwְ7:HZlP{y= E eiQ{eeq%@Rl& ԩg<f ,ߓQYEYt$b ۔OTg0|w\'B)0B5LGKB=z*%uq25y<`dcyBd{1b%kN\o>Ab!IÁ;[(7 Jt [h j~ȱ 5<%o͓͕?&?FwLuֺ ,$Z8cff" 5Ș5K1p@{& ϓ Ͷ٩F4g919l4'EQVs[iL2j`I鈮(ֵU\ p`(V]rCA_ DZ{FْIl* vM " #֜#'XZ/*z lTpwze$$S,OhIbL_\O󨅸]cfH4 jM&BKcV㡌~G/u˂$5l n~;^d(䤫62KCɞO\̼V'.=ˆ^Kb`*ߜQ Ogs}СEO,~ȿُ"9XtJ]ݿW8 9~^ʛDZvh*\/O>y1$;3tOFYo˱>bh,^`P *&_--NAg D;Jv f#XD'<:"l^+涞HYH@,:8Dc`Nظmx" ڲIaB?>.DRo⁖$_P? E(~7+[7L 6wb2 M{IЀ-s90;ۧ*)D5NS,(lۓ=wJ~wtt1 C0G<.,)8uV&{ic͛ \#~+ r:[LY ʃ7:X't@LC$oaӟسAñ}P4}u`H & ɽ}/hѭiݪр"{})hkU v%;NlP6xuod?\WD8dץ Jͱ]|hCqkpj;7(Bm+ ګ,tIv&'_IK(]"2 70: UY s?Ծܛm29XVy#yp.H|=xv#EZ'P% ,(2[*qR _.Il̯5 ubLKAIgb, Bqh bTyR D)T w\.6v<T$<|]htR-b2Z?'"#Hi.<ΗRidUQO%lVӐXrZ<ʥFzA]j.Q"OwSWJMZo۵.ݭx̎{gOһejzjm&$ҵ z.lsađe4P3,XZ*HI?wѩ<Pe@ѷЧDzɄp#]lyɄbsN^5V sҝK^$Il':GE8EeM=ଥjsZ5LnIXad.\tP 䴰y.yO}0f{(YԎJH,x!C?L ~gQI!cf-ώuU=ǰw%myi6On%1~c1/ap+cQ4MgX=ĻGX2}a{"fEl{?qTwFԠLwk-U#ܖtZxX'v/MqM6Y^^G\ ?au`3!4wG9_/-~7IfV0@T9\<\TC! v[PvlM3 &Py>Otte~Б ̨C} Ҩw5=+`Ž=r2a]Cw`%֩.+Ʀa5 h#v9fĸ)4'gSu"y; w@Znhev/,E* m!g;@n]`mhDX\Ho'otr nAHL2n1|Q^>U $rboMks}g!k4Ub'Go;g;n7t`KB`i ZQK:%FbEҔ}<)4!?$K N28dY辥Y{Y }` ()mMArࣖ--gqV$2bah4uʏ^R#b.5~N=3x8FmmB$;WXV D p3/6I2Cv9,=b3 q,, 2)ع=G\liTԁ5Q?Kڶf 輲^8fN=>CnV ]LЎ(̐4&]B848wBep564rLYp3>CNlՆU9ኞ0a/$_l:kVuX̙ ?LR\̈poml갰pOp -tU?nm Oi6|KiYE_*u3Oh3#t^Ϥ ߷H@XDv@mdpNظw \/}ȹBeڸ"28ORv-~Q̙ i _lpWP B?˙d6N8Q_i&QjiY%2XD.Kf{ u:dS(`ue`tVUD7k;P\&$hT|A;}&^=Ѫb걠7;h[2ӤrgR{D^Ql#Fa:rXf4,ѭ7O V-$H$pam "LA>m{l ̼۟Շ?`9G{eDc/Lhd`iZzPچ: }nU\v&S ,c(2f,2X] DBZ:%ސ3餛_:rbP8FyO+ºtB#e`+') YZ